Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set httpOnly flag for session language cookie #17271

Merged
merged 1 commit into from Feb 25, 2021
Merged

Conversation

sgiehl
Copy link
Member

@sgiehl sgiehl commented Feb 25, 2021

Description:

Seems the matomo_lang cookie is only used in PHP scripts and not in any javascripts. So should be fine to add the httpOnly flag I guess.

fixes #17270

Review

  • Functional review done
  • Usability review done (is anything maybe unclear or think about anything that would cause people to reach out to support)
  • Security review done see checklist
  • Code review done
  • Tests were added if useful/possible
  • Reviewed for breaking changes
  • Developer changelog updated if needed
  • Documentation added if needed
  • Existing documentation updated if needed

@sgiehl sgiehl added not-in-changelog For issues or pull requests that should not be included in our release changelog on matomo.org. Needs Review PRs that need a code review labels Feb 25, 2021
@diosmosis diosmosis merged commit 379a712 into 4.x-dev Feb 25, 2021
@diosmosis diosmosis deleted the langcookiehttp branch February 25, 2021 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Needs Review PRs that need a code review not-in-changelog For issues or pull requests that should not be included in our release changelog on matomo.org.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Make all cookies httpOnly
2 participants