Req #72230 [Com]: Add SameSite Cookies to setcookie()
| From: | xistence at 0x90 dot nl | Date: | Thu, 01 Dec 2016 10:08:47 +0000 |
| Subject: | Req #72230 [Com]: Add SameSite Cookies to setcookie() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205707@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72230&edit=1
ID: 72230
Comment by: xistence at 0x90 dot nl
Reported by: love at sickpeople dot se
Summary: Add SameSite Cookies to setcookie()
Status: Open
Type: Feature/Change Request
Package: Unknown/Other Function
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
I've created a patch that adds support for the SameSite cookie attribute in the setcookie()
function.
The samesite value can be set like this through setcookie(), note that the last function argument is
the samesite value ("Lax" in this case):
<?php setcookie("TestCookie", 31337, time()+3600, "/",
"thisdomain.com", 1, 1, "Lax" ); ?>
Retrieving the headers shows the SameSite=Lax cookie attribute being set:
$ curl -I http://X.X.X.X/index.php
HTTP/1.1 200 OK
Date: Thu, 01 Dec 2016 10:06:55 GMT
Server: Apache/2.4.6 (CentOS) PHP/7.0.13 OpenSSL/1.0.1e-fips
X-Powered-By: PHP/7.0.13
Set-Cookie: TestCookie=31337; expires=Thu, 01-Dec-2016 11:06:55 GMT; Max-Age=3600; path=/;
domain=thisdomain.com; secure; HttpOnly; SameSite=Lax
Content-Type: text/html; charset=UTF-8
This also adds the session.cookie_samesite INI setting as mentioned in bug ID #73454
As mentioned before, one should not set this to "true" to enable, but use one of the
currently supported values of "Lax" or "Strict" as mentioned in the RFC.
These are the settings currently supported by Chrome and Opera (And probably soon in Firefox/Edge)
Previous Comments:
------------------------------------------------------------------------
[2016-11-03 16:05:29] love at sickpeople dot se
Bug for adding INI session.cookie_samesite: https://bugs.php.net/bug.php?id=73454
------------------------------------------------------------------------
[2016-10-04 13:22:50] marcus at synchromedia dot co dot uk
true isn't a good option - it should accept only the defined values from the RFC
(https://tools.ietf.org/html/draft-west-first-party-cookies-07#section-3.1), i.e.
Strict or Lax.
------------------------------------------------------------------------
[2016-05-17 11:29:56] love at sickpeople dot se
Description:
------------
Add a new parameter to setcookie()
- Name: samesite
- Default value: false
- If true, sets the SameSite flag
In short, this helps security by protecting against CSRF, XSSI and others (see link below).
Update to RFC 6265: https://tools.ietf.org/html/draft-west-first-party-cookies-07
Implemented in Chrome: https://bugs.chromium.org/p/chromium/issues/detail?id=459154
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72230&edit=1