From 07358bb652ff07a8a925a9ed007ded1c5a95ba5e Mon Sep 17 00:00:00 2001 From: alec Date: Fri, 5 Dec 2008 08:07:17 +0000 Subject: #1485461: secure initial login form sesssion cookie git-svn-id: https://svn.roundcube.net/trunk@2123 208e9e7b-5314-0410-a742-e7e81cd9613c --- roundcubemail/program/include/iniset.php | 1 + 1 file changed, 1 insertion(+) (limited to 'roundcubemail/program') diff --git a/roundcubemail/program/include/iniset.php b/roundcubemail/program/include/iniset.php index 2be15b1a5..fda13e9cf 100755 --- a/roundcubemail/program/include/iniset.php +++ b/roundcubemail/program/include/iniset.php @@ -53,6 +53,7 @@ if (set_include_path($include_path) === false) { ini_set('session.name', 'roundcube_sessid'); ini_set('session.use_cookies', 1); ini_set('session.only_use_cookies', 1); +ini_set('session.cookie_secure', ($_SERVER['HTTPS'] && ($_SERVER['HTTPS'] != 'off'))); ini_set('error_reporting', E_ALL&~E_NOTICE); set_magic_quotes_runtime(0); -- cgit v1.2.3