Set a secure flag to a redis session key

Looking at the headers in Chrome, specifically set-cookie for this header. This is the case in both dev and prod environments.

@voltone I haven’t gotten too far into Endpoint configuration, I was called away to some other things today but I will look into that and let you know how it goes.