make cookies strict

This commit is contained in:
Dennis Eichhorn 2020-02-01 15:16:17 +01:00
parent 30a8fe202e
commit f1bbb2abe3
2 changed files with 2 additions and 2 deletions

View File

@ -194,7 +194,7 @@ final class CookieJar
// @codeCoverageIgnoreStart
foreach ($this->cookies as $key => $cookie) {
\setcookie($key, $cookie['value'], $cookie['expiry'], $cookie['path'], $cookie['domain'], $cookie['secure'], $cookie['httponly']);
\setcookie($key, $cookie['value'], $cookie['expiry'], $cookie['path'], $cookie['domain'], $cookie['secure'], $cookie['httponly'], ['samesite'=>'Strict']);
}
// @codeCoverageIgnoreEnd
}

View File

@ -85,7 +85,7 @@ final class HttpSession implements SessionInterface
$this->inactivityInterval = $inactivityInterval;
if (\session_status() !== \PHP_SESSION_ACTIVE && !\headers_sent()) {
\session_set_cookie_params($liftetime, '/', '', false, true); // @codeCoverageIgnore
\session_set_cookie_params($liftetime, '/', '', false, true, ['samesite'=>'Strict']); // @codeCoverageIgnore
\session_start(); // @codeCoverageIgnore
}