Re: httpOnly Cookies [tiny enhancement]

From: Date: Thu, 23 Jun 2005 23:19:10 +0000
Subject: Re: httpOnly Cookies [tiny enhancement]
Groups: php.internals 
Request: Send a blank email to internals+get-16888@lists.php.net to get a copy of this message
Hello, >Jani: Provide the patch against CVS HEAD branch. You can find the patches for httpOnly session cookies against the PHP5 CVS HEAD in the attachment. Now also included is support for httpOnly cookies for PHP functions setcookie() and setrawcookie(). bool setcookie ( string name [, string value [, int expire [, string path [, string domain [, bool secure [, bool httponly]]]]] ) bool setrawcookie ( string name [, string value [, int expire [, string path [, string domain [, bool secure [, bool httponly]]]]] ) Default value for httponly is 0. > Steven: IE on Mac fails to recognize such cookies. You will have to code around this browser bug. An easy hack around this is to identify that browser by use of browscap.ini and then code something like this for session cookies: if(IE-MAC) { session_set_cookie_params(ini_get("session.cookie_lifetime"),ini_get("session.cookie_path"),ini_get("session.cookie_domain"),ini_get("session.cookie_secure"),0); } session_start(); Jochen [ext/session/session.c.patch ; ext/session/php_session.h.patch ; ext/standard/head.c.patch ; ext/standard/head.h.patch]

Attachment: [text/x-patch] php_session.h.patch
Attachment: [text/x-patch] session.c.patch
Attachment: [text/x-patch] head.c.patch
Attachment: [text/x-patch] head.h.patch
« previous php.internals (#16888) next »