HOR-1284: Security Issue - Session Cookie Without Secure Flag
.
This commit is contained in:
@@ -897,7 +897,7 @@ if (! defined( 'EXECUTE_BY_CRON' )) {
|
||||
if (PHP_VERSION < 5.2) {
|
||||
setcookie(session_name(), session_id(), time() + $timelife, '/', '; HttpOnly');
|
||||
} else {
|
||||
setcookie(session_name(), session_id(), time() + $timelife, '/', null, false, true);
|
||||
setcookie(session_name(), session_id(), time() + $timelife, '/', null, G::is_https(), true);
|
||||
}
|
||||
}
|
||||
$RBAC->initRBAC();
|
||||
@@ -974,7 +974,7 @@ if (! defined( 'EXECUTE_BY_CRON' )) {
|
||||
if (PHP_VERSION < 5.2) {
|
||||
setcookie(session_name(), session_id(), time() + $timelife, '/', '; HttpOnly');
|
||||
} else {
|
||||
setcookie(session_name(), session_id(), time() + $timelife, '/', null, false, true);
|
||||
setcookie(session_name(), session_id(), time() + $timelife, '/', null, G::is_https(), true);
|
||||
}
|
||||
}
|
||||
$RBAC->initRBAC();
|
||||
|
||||
Reference in New Issue
Block a user