Add Secure flag (HTTPS only) to cookies

This commit is contained in:
Marcus Hill
2022-01-09 13:56:45 +00:00
parent 8d5a8edada
commit 25b58c21c8
3 changed files with 13 additions and 3 deletions

View File

@@ -1,9 +1,13 @@
<?php
if(!isset($_SESSION)){
// HTTP Only cookies
ini_set("session.cookie_httponly", True);
session_start();
// HTTP Only cookies
ini_set("session.cookie_httponly", True);
if($config_https_only){
// Tell client to only send cookie(s) over HTTPS
ini_set("session.cookie_secure", True);
}
session_start();
}
//Check to see if setup is enabled