Req #72230 [Com]: Add SameSite Cookies to setcookie()

From: Date: Thu, 01 Dec 2016 10:08:47 +0000
Subject: Req #72230 [Com]: Add SameSite Cookies to setcookie()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205707@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72230&edit=1 ID: 72230 Comment by: xistence at 0x90 dot nl Reported by: love at sickpeople dot se Summary: Add SameSite Cookies to setcookie() Status: Open Type: Feature/Change Request Package: Unknown/Other Function PHP Version: Irrelevant Block user comment: N Private report: N New Comment: I've created a patch that adds support for the SameSite cookie attribute in the setcookie() function. The samesite value can be set like this through setcookie(), note that the last function argument is the samesite value ("Lax" in this case): <?php setcookie("TestCookie", 31337, time()+3600, "/", "thisdomain.com", 1, 1, "Lax" ); ?> Retrieving the headers shows the SameSite=Lax cookie attribute being set: $ curl -I http://X.X.X.X/index.php HTTP/1.1 200 OK Date: Thu, 01 Dec 2016 10:06:55 GMT Server: Apache/2.4.6 (CentOS) PHP/7.0.13 OpenSSL/1.0.1e-fips X-Powered-By: PHP/7.0.13 Set-Cookie: TestCookie=31337; expires=Thu, 01-Dec-2016 11:06:55 GMT; Max-Age=3600; path=/; domain=thisdomain.com; secure; HttpOnly; SameSite=Lax Content-Type: text/html; charset=UTF-8 This also adds the session.cookie_samesite INI setting as mentioned in bug ID #73454 As mentioned before, one should not set this to "true" to enable, but use one of the currently supported values of "Lax" or "Strict" as mentioned in the RFC. These are the settings currently supported by Chrome and Opera (And probably soon in Firefox/Edge) Previous Comments: ------------------------------------------------------------------------ [2016-11-03 16:05:29] love at sickpeople dot se Bug for adding INI session.cookie_samesite: https://bugs.php.net/bug.php?id=73454 ------------------------------------------------------------------------ [2016-10-04 13:22:50] marcus at synchromedia dot co dot uk true isn't a good option - it should accept only the defined values from the RFC (https://tools.ietf.org/html/draft-west-first-party-cookies-07#section-3.1), i.e. Strict or Lax. ------------------------------------------------------------------------ [2016-05-17 11:29:56] love at sickpeople dot se Description: ------------ Add a new parameter to setcookie() - Name: samesite - Default value: false - If true, sets the SameSite flag In short, this helps security by protecting against CSRF, XSSI and others (see link below). Update to RFC 6265: https://tools.ietf.org/html/draft-west-first-party-cookies-07 Implemented in Chrome: https://bugs.chromium.org/p/chromium/issues/detail?id=459154 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72230&edit=1

« previous php.bugs (#205707) next »