I want to make my session cookie HttpOnly
. Based on this article, I added this to my application.ini
:
resources.session.cookie_httponly = true
Unfortunately, when I look at the session cookie in Firecookie, it is not marked as HttpOnly
as I have specified. What step am I missing?
Add this to your application.ini file.
phpSettings.session.cookie_httponly = true
Try at bootstrap to do Zend_Session::setOptions(array('cookie_httponly' => true));
( somewhere before the session is first initialized ) tough it should work with the app.ini file too .
For this to be 100% safe.
The server should not allow the option http trace. The http option trace reports the session id. If a attacker can inject a java applet, flash or javascript with ajax the attacker can also steal cookies even with the httponly flag set...
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With