Req #72230 [Ver->Csd]: Add SameSite Cookies to setcookie()
| From: | carusogabriel@php.net | Date: | Sun, 05 Aug 2018 04:56:34 +0000 |
| Subject: | Req #72230 [Ver->Csd]: Add SameSite Cookies to setcookie() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216598@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72230&edit=1
ID: 72230
Updated by: carusogabriel@php.net
Reported by: love at sickpeople dot se
Summary: Add SameSite Cookies to setcookie()
-Status: Verified
+Status: Closed
Type: Feature/Change Request
Package: *Network Functions
PHP Version: Irrelevant
-Assigned To:
+Assigned To: carusogabriel
Block user comment: N
Private report: N
New Comment:
Closing as it was implemented via http://git.php.net/?p=php-src.git;a=commit;h=08b9310e
and http://git.php.net/?p=php-src.git;a=commit;h=2b58ab23
Previous Comments:
------------------------------------------------------------------------
[2018-03-11 23:47:31] cmb@php.net
The <https://wiki.php.net/rfc/same-site-cookie>
RFC has been
accepted quite a while ago, but the implementation is still
missing. A respective PR would be welcome!
------------------------------------------------------------------------
[2017-09-14 17:49:42] cmb@php.net
Note that there is already a respective RFC (targetting PHP 7.3.0)
in voting phase: <https://wiki.php.net/rfc/same-site-cookie>.
------------------------------------------------------------------------
[2017-02-21 13:50:40] narf at devilix dot net
@xistence I noticed a small bug in the patch, here:
+ if (samesite) {
+ len += ZSTR_LEN(domain);
+ }
... should be ZSTR_LEN(samesite)
But either way, it would get more attention if you submit a PR through GitHub and start a discussion
about it on the php-internals@ mailing list.
I'd like to see this happen ASAP, but I'm guessing the maintainers would opt to see what
happens with https://tools.ietf.org/html/draft-west-first-party-cookies-07
first (and to be honest - that's reasonable).
------------------------------------------------------------------------
[2017-02-21 13:37:45] marcus at synchromedia dot co dot uk
I agree with that, constants a better idea than strings.
Good new article on using this cookie flag: https://scotthelme.co.uk/csrf-is-dead/
This should go into PHP ASAP, it's a vital security feature.
------------------------------------------------------------------------
[2017-02-21 12:46:46] ale dot comp_06 at xox dot ch
what about using constants (Cookies::SAMESITE_LAX ?) instead of strings?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72230
--
Edit this bug report at https://bugs.php.net/bug.php?id=72230&edit=1