Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Modifying other php.ini params #12

Open
juanluisbaptiste opened this issue Feb 3, 2021 · 0 comments
Open

Modifying other php.ini params #12

juanluisbaptiste opened this issue Feb 3, 2021 · 0 comments

Comments

@juanluisbaptiste
Copy link

Hi David how are ya ? happy new year !!

Last week I had to do a security audit of some sites and on the report, a couple issues came along that to fix them a couple options in php.ini can me added. Their about cookie security, the httpOnly set-cookie response header and secure cookie attribute.

They can be configured by setting the session.http_only and session.cookie_secure respectively in php.ini.

What do you think about this ? could it be possible to have some options to increase security and enable this parameters ?

Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant