From a7f2c060b2456d389aec9d7ddf127a2b8ff1bb82 Mon Sep 17 00:00:00 2001 From: Yitzchok Willroth Date: Thu, 29 Jun 2017 12:09:59 -0400 Subject: [PATCH] :wrench: :wrench: Reduce discoverability of session cookie name. Derives session.cookie from SESSION_COOKIE, falling back to (snake_cased) APP_NAME . '_session', falling back to 'laravel_session' (current) in order to make it less discoverable, thereby (slightly) reducing threat vector. --- config/session.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/session.php b/config/session.php index f222f747..6d65251d 100644 --- a/config/session.php +++ b/config/session.php @@ -122,7 +122,7 @@ | */ - 'cookie' => 'laravel_session', + 'cookie' => env('SESSION_COOKIE', snake_case(env('APP_NAME', 'laravel')).'_session'), /* |--------------------------------------------------------------------------