diff --git a/artisan b/artisan index 66a0cc09..8f7bfe4e 100644 --- a/artisan +++ b/artisan @@ -3,7 +3,7 @@ * Laravel - A PHP Framework For Web Artisans * * @package Laravel - * @version 3.1.4 + * @version 3.1.5 * @author Taylor Otwell * @link http://laravel.com */ diff --git a/laravel/cookie.php b/laravel/cookie.php index fc48212e..0f92818f 100644 --- a/laravel/cookie.php +++ b/laravel/cookie.php @@ -63,6 +63,14 @@ protected static function set($cookie) } else { + // We don't want to send secure cookies over HTTP unless the developer has + // turned off the "SSL" application configuration option, which is used + // while developing the application but should be true in production. + if ($secure and ! Request::secure() and Config::get('application.ssl')) + { + return; + } + setcookie($name, $value, $time, $path, $domain, $secure); } } diff --git a/laravel/documentation/changes.md b/laravel/documentation/changes.md index 2cdaae61..0047ff83 100644 --- a/laravel/documentation/changes.md +++ b/laravel/documentation/changes.md @@ -4,6 +4,8 @@ ## Contents - [Laravel 3.2](#3.2) - [Upgrading From 3.1](#upgrade-3.2) +- [Laravel 3.1.5](#3.1.5) +- [Upgrading From 3.1.4](#upgrade-3.1.5) - [Laravel 3.1.4](#3.1.4) - [Upgrading From 3.1.3](#upgrade-3.1.4) - [Laravel 3.1.3](#3.1.3) @@ -33,6 +35,16 @@ ## Upgrading From 3.1 - Replace the **laravel** folder. - Add new **vendors** folder. + +## Laravel 3.1.5 + +- Fixes bug that could allow secure cookies to be sent over HTTP. + + +## Upgrading From 3.1.4 + +- Replace the **laravel** folder. + ## Laravel 3.1.4 diff --git a/paths.php b/paths.php index afc2bf58..0f44dd30 100644 --- a/paths.php +++ b/paths.php @@ -3,7 +3,7 @@ * Laravel - A PHP Framework For Web Artisans * * @package Laravel - * @version 3.1.4 + * @version 3.1.5 * @author Taylor Otwell * @link http://laravel.com */ diff --git a/public/index.php b/public/index.php index 561d13a3..56896d97 100644 --- a/public/index.php +++ b/public/index.php @@ -3,7 +3,7 @@ * Laravel - A PHP Framework For Web Artisans * * @package Laravel - * @version 3.1.4 + * @version 3.1.5 * @author Taylor Otwell * @link http://laravel.com */