Add Secure flag (HTTPS only) to cookies

This commit is contained in:
Marcus Hill
2022-01-09 13:56:45 +00:00
parent 8d5a8edada
commit 25b58c21c8
3 changed files with 13 additions and 3 deletions

View File

@@ -19,6 +19,11 @@ $user_agent = "$os - $browser";
// HTTP Only cookies
ini_set("session.cookie_httponly", True);
// Tell client to only send cookie(s) over HTTPS
if($config_https_only){
ini_set("session.cookie_secure", True);
}
session_start();
if(isset($_POST['login'])){