Req #72230 [Ver->Csd]: Add SameSite Cookies to setcookie()

From: Date: Sun, 05 Aug 2018 04:56:34 +0000
Subject: Req #72230 [Ver->Csd]: Add SameSite Cookies to setcookie()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216598@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72230&edit=1 ID: 72230 Updated by: carusogabriel@php.net Reported by: love at sickpeople dot se Summary: Add SameSite Cookies to setcookie() -Status: Verified +Status: Closed Type: Feature/Change Request Package: *Network Functions PHP Version: Irrelevant -Assigned To: +Assigned To: carusogabriel Block user comment: N Private report: N New Comment: Closing as it was implemented via http://git.php.net/?p=php-src.git;a=commit;h=08b9310e and http://git.php.net/?p=php-src.git;a=commit;h=2b58ab23 Previous Comments: ------------------------------------------------------------------------ [2018-03-11 23:47:31] cmb@php.net The <https://wiki.php.net/rfc/same-site-cookie> RFC has been accepted quite a while ago, but the implementation is still missing. A respective PR would be welcome! ------------------------------------------------------------------------ [2017-09-14 17:49:42] cmb@php.net Note that there is already a respective RFC (targetting PHP 7.3.0) in voting phase: <https://wiki.php.net/rfc/same-site-cookie>. ------------------------------------------------------------------------ [2017-02-21 13:50:40] narf at devilix dot net @xistence I noticed a small bug in the patch, here: + if (samesite) { + len += ZSTR_LEN(domain); + } ... should be ZSTR_LEN(samesite) But either way, it would get more attention if you submit a PR through GitHub and start a discussion about it on the php-internals@ mailing list. I'd like to see this happen ASAP, but I'm guessing the maintainers would opt to see what happens with https://tools.ietf.org/html/draft-west-first-party-cookies-07 first (and to be honest - that's reasonable). ------------------------------------------------------------------------ [2017-02-21 13:37:45] marcus at synchromedia dot co dot uk I agree with that, constants a better idea than strings. Good new article on using this cookie flag: https://scotthelme.co.uk/csrf-is-dead/ This should go into PHP ASAP, it's a vital security feature. ------------------------------------------------------------------------ [2017-02-21 12:46:46] ale dot comp_06 at xox dot ch what about using constants (Cookies::SAMESITE_LAX ?) instead of strings? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72230 -- Edit this bug report at https://bugs.php.net/bug.php?id=72230&edit=1

« previous php.bugs (#216598) next »