From f05a0fd777dd9f9539a9e9f748dadea2fa258bcd Mon Sep 17 00:00:00 2001 From: Cameron Date: Sat, 13 Jan 2018 12:38:32 -0800 Subject: [PATCH] Set secure cookie when SSL active. --- e107_handlers/session_handler.php | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/e107_handlers/session_handler.php b/e107_handlers/session_handler.php index 05c7c4fed..778cb777b 100644 --- a/e107_handlers/session_handler.php +++ b/e107_handlers/session_handler.php @@ -214,6 +214,11 @@ class e_session $options['lifetime'] = (integer) e107::getPref('session_lifetime', 86400); // $options['path'] = e107::getPref('session_cookie_path', ''); // FIXME - new pref $options['secure'] = e107::getPref('ssl_enabled', false); // + + if(!empty($options['secure'])) + { + ini_set('session.cookie_secure', 1); + } } if(defined('SESSION_SAVE_PATH')) // safer than a pref.