Security - Secure session cookies by setting HttpOnly, Secure, and SameSite attributes (#7530)

This commit is contained in:
Alex
2025-09-23 15:07:31 -07:00
committed by GitHub
parent b529c713d5
commit e43b27a42d

View File

@@ -88,10 +88,13 @@
global $database;
$database = database::new(['config' => $config]);
//if not using the command line required files
//start the session if not using the command line
global $no_session;
if (!defined('STDIN') && empty($no_session)) {
require_once __DIR__ . '/php.php';
ini_set('session.cookie_httponly', 'true');
ini_set('session.cookie_secure', 'true');
ini_set('session.cookie_samesite', 'Lax');
session_start();
}
//load settings