Session cookies http & secure flag - how do you set these?

后端 未结 3 1076
生来不讨喜
生来不讨喜 2020-12-23 10:16

Just received the results of a security audit - everything clear apart from two things

Session cookie without http flag.

Session cookie without secure flag s

3条回答
  •  醉话见心
    2020-12-23 10:32

    Since you asked for .htaccess, and this setting is PHP_INI_ALL, just put this in your .htaccess:

    php_value session.cookie_httponly 1
    php_value session.cookie_secure 1
    

    Note that session cookies will only be sent with https requests after that. This might come as a surprise if you lose a session in non-secured http page (but like pointed out in the comments, is really the point of the configuration in the first place...).

提交回复
热议问题