Hello. Does anyone know how to fix this scan problem: Session Cookie Does Not Contain the "Secure" Attribute?
OC 3.3.0.1 on php 7.2, site is fully on https
In system/framework.php change.
To.
In catalog/controller/startup/session.php change.
To.
Instead in true, true you could use ini_get('session.cookie_secure'), ini_get('session.cookie_httponly') if you have configured them to On.
Code: Select all
setcookie($config->get('session_name'), $session->getId(), ini_get('session.cookie_lifetime'), ini_get('session.cookie_path'), ini_get('session.cookie_domain'));
Code: Select all
setcookie($config->get('session_name'), $session->getId(), ini_get('session.cookie_lifetime'), ini_get('session.cookie_path'), ini_get('session.cookie_domain'), true, true);
Code: Select all
setcookie($this->config->get('session_name'), $this->session->getId(), ini_get('session.cookie_lifetime'), ini_get('session.cookie_path'), ini_get('session.cookie_domain'));
Code: Select all
setcookie($this->config->get('session_name'), $this->session->getId(), ini_get('session.cookie_lifetime'), ini_get('session.cookie_path'), ini_get('session.cookie_domain'), true, true);
Who is online
Users browsing this forum: No registered users and 13 guests