Add httponly setting to cookies in check_login before session starts there too. Extension of pull #253
This commit is contained in:
@@ -1,6 +1,8 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
if(!isset($_SESSION)){
|
if(!isset($_SESSION)){
|
||||||
|
// HTTP Only cookies
|
||||||
|
ini_set("session.cookie_httponly", True);
|
||||||
session_start();
|
session_start();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user