[#7551] session cookies can be httpOnly; remove unused 'secret'; comments

The beaker.session.secret value is only used for storage-backed sessions,
we use the validate_key for pure cookie sessions.
2 files changed