Uploaded image for project: 'FreePBX'
  1. FreePBX
  2. FREEPBX-7570

Set HttpOnly flag in PHPSESSID cookie by default

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Minor
    • Resolution: Won't Fix
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: FreePBX Distro
    • Labels:
    • ToDo:

      Description

      PHPSESSID cookie is created by PHP without HttpOnly flag set.
      Configuring PHP in a way so this flag is set will improve security.
      Please see:
      https://www.owasp.org/index.php/HttpOnly#Using_PHP_to_set_HttpOnly

        Gliffy Diagrams

          Attachments

            Activity

              People

              • Assignee:
                tm1000 Andrew Nagy
                Reporter:
                varnav varnav
              • Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  NextupJiraPlusStatus

                  Error rendering 'slack.nextup.jira:nextup-jira-plus-status'. Please contact your Jira administrators.