#5887 - Session cookies should always be HttpOnly / Secure where applicable

This is a spacer post for a website comment topic. The content this topic relates to: #5887 - Session cookies should always be HttpOnly / Secure where applicable
Automated message: This issue was created using the Report Issue Wizard on the Composr homesite.
v11 has the same problem, although only for the Secure property; it is setting HttpOnly like it should.
Automated response: Session cookies should always be HttpOnly / Secure where applicable

This patch forces http-only on Session cookies and also correctly applies the Secure property when applicable.

This patch will not work without the updated global*.php files for 10.0.49. See GitLab to get them.

Warning: This fix causes #5888 and #5889 . See those issues for resolutions.
REVERTED in 10.0.50
0 guests and 0 members have recently viewed this.