Added http_only option to session configuration.
This commit is contained in:
parent
d6e1d5424d
commit
db45be960f
|
@ -16,7 +16,7 @@
|
||||||
|
|
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
'driver' => '',
|
'driver' => 'file',
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
|
@ -86,4 +86,19 @@
|
||||||
|
|
||||||
'https' => false,
|
'https' => false,
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| HTTP Only Session Cookie
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Should the session cookie only be accessible over HTTP?
|
||||||
|
|
|
||||||
|
| Note: The intention of the "HTTP Only" option is to keep cookies from
|
||||||
|
| being accessed by client-side scripting languages. However, this
|
||||||
|
| setting should not be viewed as providing total XSS protection.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'http_only' => false,
|
||||||
|
|
||||||
);
|
);
|
Loading…
Reference in New Issue