Skip to content

Commit

Permalink
set httponly to true when calling setcookie. the ini_set option above…
Browse files Browse the repository at this point in the history
… doesn't actually seem to do anything... (but not removing it just in case

Signed-off-by: Adam Warner <me@adamwarner.co.uk>
  • Loading branch information
PromoFaux committed Sep 11, 2021
1 parent cce6889 commit cf8602e
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions scripts/pi-hole/php/password.php
Expand Up @@ -50,7 +50,8 @@
{
$auth = true;
// Refresh cookie with new expiry
setcookie('persistentlogin', $pwhash, time()+60*60*24*7);
// setcookie( $name, $value, $expire, $path, $domain, $secure, $httponly )
setcookie('persistentlogin', $pwhash, time()+60*60*24*7, null, null, null, true );
}
else
{
Expand Down Expand Up @@ -79,7 +80,8 @@
// Set persistent cookie if selected
if (isset($_POST['persistentlogin']))
{
setcookie('persistentlogin', $pwhash, time()+60*60*24*7);
// setcookie( $name, $value, $expire, $path, $domain, $secure, $httponly )
setcookie('persistentlogin', $pwhash, time()+60*60*24*7, null, null, null, true );
}
header('Location: index.php');
exit();
Expand Down

0 comments on commit cf8602e

Please sign in to comment.