Req #72230 [Opn->Ver]: Add SameSite Cookies to setcookie()
| From: | cmb@php.net | Date: | Sun, 11 Mar 2018 23:47:36 +0000 |
| Subject: | Req #72230 [Opn->Ver]: Add SameSite Cookies to setcookie() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214292@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72230&edit=1
ID: 72230
Updated by: cmb@php.net
Reported by: love at sickpeople dot se
Summary: Add SameSite Cookies to setcookie()
-Status: Open
+Status: Verified
Type: Feature/Change Request
Package: *Network Functions
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
The <https://wiki.php.net/rfc/same-site-cookie>
RFC has been
accepted quite a while ago, but the implementation is still
missing. A respective PR would be welcome!
Previous Comments:
------------------------------------------------------------------------
[2017-09-14 17:49:42] cmb@php.net
Note that there is already a respective RFC (targetting PHP 7.3.0)
in voting phase: <https://wiki.php.net/rfc/same-site-cookie>.
------------------------------------------------------------------------
[2017-02-21 13:50:40] narf at devilix dot net
@xistence I noticed a small bug in the patch, here:
+ if (samesite) {
+ len += ZSTR_LEN(domain);
+ }
... should be ZSTR_LEN(samesite)
But either way, it would get more attention if you submit a PR through GitHub and start a discussion
about it on the php-internals@ mailing list.
I'd like to see this happen ASAP, but I'm guessing the maintainers would opt to see what
happens with https://tools.ietf.org/html/draft-west-first-party-cookies-07
first (and to be honest - that's reasonable).
------------------------------------------------------------------------
[2017-02-21 13:37:45] marcus at synchromedia dot co dot uk
I agree with that, constants a better idea than strings.
Good new article on using this cookie flag: https://scotthelme.co.uk/csrf-is-dead/
This should go into PHP ASAP, it's a vital security feature.
------------------------------------------------------------------------
[2017-02-21 12:46:46] ale dot comp_06 at xox dot ch
what about using constants (Cookies::SAMESITE_LAX ?) instead of strings?
------------------------------------------------------------------------
[2016-12-01 10:08:40] xistence at 0x90 dot nl
I've created a patch that adds support for the SameSite cookie attribute in the setcookie()
function.
The samesite value can be set like this through setcookie(), note that the last function argument is
the samesite value ("Lax" in this case):
<?php setcookie("TestCookie", 31337, time()+3600, "/",
"thisdomain.com", 1, 1, "Lax" ); ?>
Retrieving the headers shows the SameSite=Lax cookie attribute being set:
$ curl -I http://X.X.X.X/index.php
HTTP/1.1 200 OK
Date: Thu, 01 Dec 2016 10:06:55 GMT
Server: Apache/2.4.6 (CentOS) PHP/7.0.13 OpenSSL/1.0.1e-fips
X-Powered-By: PHP/7.0.13
Set-Cookie: TestCookie=31337; expires=Thu, 01-Dec-2016 11:06:55 GMT; Max-Age=3600; path=/;
domain=thisdomain.com; secure; HttpOnly; SameSite=Lax
Content-Type: text/html; charset=UTF-8
This also adds the session.cookie_samesite INI setting as mentioned in bug ID #73454
As mentioned before, one should not set this to "true" to enable, but use one of the
currently supported values of "Lax" or "Strict" as mentioned in the RFC.
These are the settings currently supported by Chrome and Opera (And probably soon in Firefox/Edge)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72230
--
Edit this bug report at https://bugs.php.net/bug.php?id=72230&edit=1