Commit db45be96 by Taylor Otwell

Added http_only option to session configuration.

parent d6e1d542
...@@ -16,7 +16,7 @@ return array( ...@@ -16,7 +16,7 @@ return array(
| |
*/ */
'driver' => '', 'driver' => 'file',
/* /*
|-------------------------------------------------------------------------- |--------------------------------------------------------------------------
...@@ -86,4 +86,19 @@ return array( ...@@ -86,4 +86,19 @@ return array(
'https' => false, 'https' => false,
/*
|--------------------------------------------------------------------------
| HTTP Only Session Cookie
|--------------------------------------------------------------------------
|
| Should the session cookie only be accessible over HTTP?
|
| Note: The intention of the "HTTP Only" option is to keep cookies from
| being accessed by client-side scripting languages. However, this
| setting should not be viewed as providing total XSS protection.
|
*/
'http_only' => false,
); );
\ No newline at end of file
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment