Page 1 of 1

httponly-flag for session-cookie possible?

Posted: Wed Dec 29, 2010 6:56 pm
by gingabot
Hi,

Is it possible to set the httponly-flag for the PHPSESSID-cookie? In other words: Are there any client-side scripts within OC that need access to this cookie?

Greetz

Re: httponly-flag for session-cookie possible?

Posted: Mon Oct 22, 2012 8:39 pm
by Demon5
I could use this also since PCI cert is pending that fix.