Skip to content
Snippets Groups Projects
Commit 3b4d288c authored by Benni Mack's avatar Benni Mack
Browse files

[BUGFIX] Streamline cookie options / remove cookieHttpOnly

The TYPO3_CONF_VARS[SYS][cookieHttpOnly] option is removed
as all cookies set by the TYPO3 Core are HttpOnly by default
in order to avoid client side script access.

This option was previously turned on by default but configurable
as old browser did not support this option all the time (see
https://www.owasp.org/index.php/HttpOnly#Browsers_Supporting_HttpOnly
for more details).

The be_lastLoginProvider and workspaces cookies now
set the httpOnly flag properly as well.

Resolves: #78835
Releases: master
Change-Id: I12538508a6f97888d7ad0b2f5f028bcde2844d6d
Reviewed-on: https://review.typo3.org/50808


Reviewed-by: default avatarWouter Wolters <typo3@wouterwolters.nl>
Tested-by: default avatarWouter Wolters <typo3@wouterwolters.nl>
Reviewed-by: default avatarMarkus Klein <markus.klein@typo3.org>
Tested-by: default avatarMarkus Klein <markus.klein@typo3.org>
Tested-by: default avatarTYPO3com <no-reply@typo3.com>
Reviewed-by: default avatarBenni Mack <benni@typo3.org>
Tested-by: default avatarBenni Mack <benni@typo3.org>
parent 958f6cdc
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment