Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory fusiondirectory
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 33
    • Issues 33
    • List
    • Boards
    • Service Desk
    • Milestones
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Terraform modules
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectoryfusiondirectory
  • Issues
  • #6217
Closed
Open
Issue created Jul 04, 2022 by bmortier@bmortierMaintainer

[Security] - Set Cookie settings to TRUE for option "HttpOnly"

Requirements

Security enhancement - it is desirable to set the cookie (upon login page) settings to TRUE for attribute HttpOnly.

"HttpOnly" option makes sure that XSS code injected though JavaScript will be refused by the browser.

To be integrated within 1.3-fixes and 1.4-dev.

Descriptive title for this enhancement

[Security] - Set Cookie settings to TRUE for option "HttpOnly">

Actual behavior

Cookie HttpOnly is set to FALSE

Expected behavior

HttpOnly set to TRUE

Step by step description of new behaviour

Update php.ini to set HttpOnly cookie option to TRUE.

Benefits

Less possible attack coming from inject of javascript XSS

Possible Drawbacks

None

Applicable Issues

None

Edited Jul 04, 2022 by bmortier
Assignee
Assign to
Time tracking