Req #72230 [Opn]: Add SameSite Cookies to setcookie()

From: Date: Thu, 14 Sep 2017 17:49:48 +0000
Subject: Req #72230 [Opn]: Add SameSite Cookies to setcookie()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211163@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72230&edit=1 ID: 72230 Updated by: cmb@php.net Reported by: love at sickpeople dot se Summary: Add SameSite Cookies to setcookie() Status: Open Type: Feature/Change Request Package: Unknown/Other Function PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Note that there is already a respective RFC (targetting PHP 7.3.0) in voting phase: <https://wiki.php.net/rfc/same-site-cookie>. Previous Comments: ------------------------------------------------------------------------ [2017-02-21 13:50:40] narf at devilix dot net @xistence I noticed a small bug in the patch, here: + if (samesite) { + len += ZSTR_LEN(domain); + } ... should be ZSTR_LEN(samesite) But either way, it would get more attention if you submit a PR through GitHub and start a discussion about it on the php-internals@ mailing list. I'd like to see this happen ASAP, but I'm guessing the maintainers would opt to see what happens with https://tools.ietf.org/html/draft-west-first-party-cookies-07 first (and to be honest - that's reasonable). ------------------------------------------------------------------------ [2017-02-21 13:37:45] marcus at synchromedia dot co dot uk I agree with that, constants a better idea than strings. Good new article on using this cookie flag: https://scotthelme.co.uk/csrf-is-dead/ This should go into PHP ASAP, it's a vital security feature. ------------------------------------------------------------------------ [2017-02-21 12:46:46] ale dot comp_06 at xox dot ch what about using constants (Cookies::SAMESITE_LAX ?) instead of strings? ------------------------------------------------------------------------ [2016-12-01 10:08:40] xistence at 0x90 dot nl I've created a patch that adds support for the SameSite cookie attribute in the setcookie() function. The samesite value can be set like this through setcookie(), note that the last function argument is the samesite value ("Lax" in this case): <?php setcookie("TestCookie", 31337, time()+3600, "/", "thisdomain.com", 1, 1, "Lax" ); ?> Retrieving the headers shows the SameSite=Lax cookie attribute being set: $ curl -I http://X.X.X.X/index.php HTTP/1.1 200 OK Date: Thu, 01 Dec 2016 10:06:55 GMT Server: Apache/2.4.6 (CentOS) PHP/7.0.13 OpenSSL/1.0.1e-fips X-Powered-By: PHP/7.0.13 Set-Cookie: TestCookie=31337; expires=Thu, 01-Dec-2016 11:06:55 GMT; Max-Age=3600; path=/; domain=thisdomain.com; secure; HttpOnly; SameSite=Lax Content-Type: text/html; charset=UTF-8 This also adds the session.cookie_samesite INI setting as mentioned in bug ID #73454 As mentioned before, one should not set this to "true" to enable, but use one of the currently supported values of "Lax" or "Strict" as mentioned in the RFC. These are the settings currently supported by Chrome and Opera (And probably soon in Firefox/Edge) ------------------------------------------------------------------------ [2016-11-03 16:05:29] love at sickpeople dot se Bug for adding INI session.cookie_samesite: https://bugs.php.net/bug.php?id=73454 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72230 -- Edit this bug report at https://bugs.php.net/bug.php?id=72230&edit=1

« previous php.bugs (#211163) next »