Bind cookie gotten over HTTPS to HTTPS only (#1485336).

release-0.6
svncommit 16 years ago
parent cc0d55cbcb
commit d0b973cf6a

@ -184,7 +184,8 @@ function rcube_sess_regenerate_id()
$lifetime = $cookie['lifetime'] ? time() + $cookie['lifetime'] : 0;
setcookie(session_name(), '', time() - 3600);
setcookie(session_name(), $random, $lifetime, $cookie['path'], $cookie['domain']);
setcookie(session_name(), $random, $lifetime, $cookie['path'], $cookie['domain'],
$_SERVER['HTTPS'] && ($_SERVER['HTTPS']!='off'));
return true;
}

Loading…
Cancel
Save