Req #72230 [Opn->Ver]: Add SameSite Cookies to setcookie()

From: Date: Sun, 11 Mar 2018 23:47:36 +0000
Subject: Req #72230 [Opn->Ver]: Add SameSite Cookies to setcookie()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214292@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72230&edit=1 ID: 72230 Updated by: cmb@php.net Reported by: love at sickpeople dot se Summary: Add SameSite Cookies to setcookie() -Status: Open +Status: Verified Type: Feature/Change Request Package: *Network Functions PHP Version: Irrelevant Block user comment: N Private report: N New Comment: The <https://wiki.php.net/rfc/same-site-cookie> RFC has been accepted quite a while ago, but the implementation is still missing. A respective PR would be welcome! Previous Comments: ------------------------------------------------------------------------ [2017-09-14 17:49:42] cmb@php.net Note that there is already a respective RFC (targetting PHP 7.3.0) in voting phase: <https://wiki.php.net/rfc/same-site-cookie>. ------------------------------------------------------------------------ [2017-02-21 13:50:40] narf at devilix dot net @xistence I noticed a small bug in the patch, here: + if (samesite) { + len += ZSTR_LEN(domain); + } ... should be ZSTR_LEN(samesite) But either way, it would get more attention if you submit a PR through GitHub and start a discussion about it on the php-internals@ mailing list. I'd like to see this happen ASAP, but I'm guessing the maintainers would opt to see what happens with https://tools.ietf.org/html/draft-west-first-party-cookies-07 first (and to be honest - that's reasonable). ------------------------------------------------------------------------ [2017-02-21 13:37:45] marcus at synchromedia dot co dot uk I agree with that, constants a better idea than strings. Good new article on using this cookie flag: https://scotthelme.co.uk/csrf-is-dead/ This should go into PHP ASAP, it's a vital security feature. ------------------------------------------------------------------------ [2017-02-21 12:46:46] ale dot comp_06 at xox dot ch what about using constants (Cookies::SAMESITE_LAX ?) instead of strings? ------------------------------------------------------------------------ [2016-12-01 10:08:40] xistence at 0x90 dot nl I've created a patch that adds support for the SameSite cookie attribute in the setcookie() function. The samesite value can be set like this through setcookie(), note that the last function argument is the samesite value ("Lax" in this case): <?php setcookie("TestCookie", 31337, time()+3600, "/", "thisdomain.com", 1, 1, "Lax" ); ?> Retrieving the headers shows the SameSite=Lax cookie attribute being set: $ curl -I http://X.X.X.X/index.php HTTP/1.1 200 OK Date: Thu, 01 Dec 2016 10:06:55 GMT Server: Apache/2.4.6 (CentOS) PHP/7.0.13 OpenSSL/1.0.1e-fips X-Powered-By: PHP/7.0.13 Set-Cookie: TestCookie=31337; expires=Thu, 01-Dec-2016 11:06:55 GMT; Max-Age=3600; path=/; domain=thisdomain.com; secure; HttpOnly; SameSite=Lax Content-Type: text/html; charset=UTF-8 This also adds the session.cookie_samesite INI setting as mentioned in bug ID #73454 As mentioned before, one should not set this to "true" to enable, but use one of the currently supported values of "Lax" or "Strict" as mentioned in the RFC. These are the settings currently supported by Chrome and Opera (And probably soon in Firefox/Edge) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72230 -- Edit this bug report at https://bugs.php.net/bug.php?id=72230&edit=1

« previous php.bugs (#214292) next »