secure cookies
| From: | Hardy Merrill | Date: | Thu, 26 Oct 2000 15:35:00 +0000 |
| Subject: | secure cookies | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-22152@lists.php.net to get a copy of this message | ||
I'm noticing that a "secure" cookie is being sent to non-secure
URL's - I set the secure cookie this way:
setcookie("foo_bar", $encrypted_foobar, 0, "", "", 1); // 1=secure
and then I redirect to a secure "https" url - but if on the URL
line you take the "s" out to make it "http", when you hit enter
the page comes up fine, and my print at the top of the script
confirms that the "secure" cookie was sent - even though the
URL is *NOT* secure.
Am I doing this wrong, or is this a bug with something?
TIA.
--
Hardy Merrill
Mission Critical Linux, Inc.
http://www.missioncriticallinux.com