8000 Change the default value of framework.session.cookie_httponly · Issue #15303 · symfony/symfony · GitHub
[go: up one dir, main page]

Skip to content
Change the default value of framework.session.cookie_httponly #15303
Closed
@jderusse

Description

@jderusse

Actually, the default value of framework.session.cookie_httponly is false, which allows javascript to read the sessionId.

To improve security, I think, we should add a BC Break by inverting this parameter.

Metadata

Metadata

Assignees

No one assigned

    Labels

    FrameworkBundleGood first issueIdeal for your first contribution! (some Symfony experience may be required)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0