Added http_only option to session configuration.
This commit is contained in:
parent
d6e1d5424d
commit
db45be960f
|
@ -16,7 +16,7 @@
|
|||
|
|
||||
*/
|
||||
|
||||
'driver' => '',
|
||||
'driver' => 'file',
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
|
@ -86,4 +86,19 @@
|
|||
|
||||
'https' => false,
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| HTTP Only Session Cookie
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Should the session cookie only be accessible over HTTP?
|
||||
|
|
||||
| Note: The intention of the "HTTP Only" option is to keep cookies from
|
||||
| being accessed by client-side scripting languages. However, this
|
||||
| setting should not be viewed as providing total XSS protection.
|
||||
|
|
||||
*/
|
||||
|
||||
'http_only' => false,
|
||||
|
||||
);
|
Loading…
Reference in New Issue