Make session cookie more secure

This commit is contained in:
Fedor A. Fetisov 2013-09-14 15:58:57 +04:00
parent 13729dac93
commit 003ba6f46b

View File

@ -15,11 +15,8 @@
* limitations under the License. * limitations under the License.
*/ */
// Prevent Mibew from access to files outside the installation
@ini_set('open_basedir', dirname(__FILE__) . '/../'); @ini_set('open_basedir', dirname(__FILE__) . '/../');
@ini_set('session.cookie_httponly', TRUE);
if (is_secure_request()) {
@ini_set('session.cookie_secure', TRUE);
}
require_once(dirname(__FILE__) . '/converter.php'); require_once(dirname(__FILE__) . '/converter.php');
require_once(dirname(__FILE__) . '/config.php'); require_once(dirname(__FILE__) . '/config.php');
@ -37,6 +34,14 @@ $home_locale = locale_pattern_check($home_locale) && locale_exists($home_locale)
$version = '1.6.5'; $version = '1.6.5';
$jsver = "165"; $jsver = "165";
// Make session cookie more secure
@ini_set('session.cookie_httponly', TRUE);
if (is_secure_request()) {
@ini_set('session.cookie_secure', TRUE);
}
@ini_set('session.cookie_path', "$webimroot/");
@ini_set('session.name', 'MibewSessionID');
session_start(); session_start();
function myiconv($in_enc, $out_enc, $string) function myiconv($in_enc, $out_enc, $string)