make cookies strict

This commit is contained in:
Dennis Eichhorn 2020-02-01 15:16:17 +01:00
parent 30a8fe202e
commit f1bbb2abe3
2 changed files with 2 additions and 2 deletions

View File

@ -194,7 +194,7 @@ final class CookieJar
// @codeCoverageIgnoreStart // @codeCoverageIgnoreStart
foreach ($this->cookies as $key => $cookie) { foreach ($this->cookies as $key => $cookie) {
\setcookie($key, $cookie['value'], $cookie['expiry'], $cookie['path'], $cookie['domain'], $cookie['secure'], $cookie['httponly']); \setcookie($key, $cookie['value'], $cookie['expiry'], $cookie['path'], $cookie['domain'], $cookie['secure'], $cookie['httponly'], ['samesite'=>'Strict']);
} }
// @codeCoverageIgnoreEnd // @codeCoverageIgnoreEnd
} }

View File

@ -85,7 +85,7 @@ final class HttpSession implements SessionInterface
$this->inactivityInterval = $inactivityInterval; $this->inactivityInterval = $inactivityInterval;
if (\session_status() !== \PHP_SESSION_ACTIVE && !\headers_sent()) { if (\session_status() !== \PHP_SESSION_ACTIVE && !\headers_sent()) {
\session_set_cookie_params($liftetime, '/', '', false, true); // @codeCoverageIgnore \session_set_cookie_params($liftetime, '/', '', false, true, ['samesite'=>'Strict']); // @codeCoverageIgnore
\session_start(); // @codeCoverageIgnore \session_start(); // @codeCoverageIgnore
} }