File tree 6 files changed +17
-5
lines changed
src/Symfony/Bundle/FrameworkBundle
Tests/DependencyInjection
6 files changed +17
-5
lines changed Original file line number Diff line number Diff line change @@ -468,6 +468,18 @@ UPGRADE FROM 2.x to 3.0
468
468
interface.
469
469
The `security.csrf.token_manager` should be used instead.
470
470
471
+ * The default value of the parameter `session`.`cookie_httponly` is now `true`.
472
+ It prevents scripting languages, such as JavaScript to access the cookie,
473
+ which help to reduce identity theft through XSS attacks. If your
474
+ application need to access the session's cookie override this parameter :
475
+
476
+ ` ` ` yaml
477
+ framework:
478
+ session:
479
+ cookie_httponly: false
480
+ ` ` `
481
+
482
+
471
483
# ## HttpKernel
472
484
473
485
* The `Symfony\Component\HttpKernel\Log\LoggerInterface` has been removed in
Original file line number Diff line number Diff line change @@ -340,7 +340,7 @@ private function addSessionSection(ArrayNodeDefinition $rootNode)
340
340
->scalarNode ('cookie_path ' )->end ()
341
341
->scalarNode ('cookie_domain ' )->end ()
342
342
->booleanNode ('cookie_secure ' )->end ()
343
- ->booleanNode ('cookie_httponly ' )->end ()
343
+ ->booleanNode ('cookie_httponly ' )->defaultValue ( true )-> end ()
344
344
->scalarNode ('gc_divisor ' )->end ()
345
345
->scalarNode ('gc_probability ' )->defaultValue (1 )->end ()
346
346
->scalarNode ('gc_maxlifetime ' )->end ()
Original file line number Diff line number Diff line change 32
32
'cookie_path ' => '/ ' ,
33
33
'cookie_domain ' => 'example.com ' ,
34
34
'cookie_secure ' => true ,
35
- 'cookie_httponly ' => true ,
35
+ 'cookie_httponly ' => false ,
36
36
'gc_maxlifetime ' => 90000 ,
37
37
'gc_divisor ' => 108 ,
38
38
'gc_probability ' => 1 ,
Original file line number Diff line number Diff line change 14
14
<framework : esi enabled =" true" />
15
15
<framework : profiler only-exceptions =" true" enabled =" false" />
16
16
<framework : router resource =" %kernel.root_dir%/config/routing.xml" type =" xml" />
17
- <framework : session gc-maxlifetime =" 90000" gc-probability =" 1" gc-divisor =" 108" storage-id =" session.storage.native" handler-id =" session.handler.native_file" name =" _SYMFONY" cookie-lifetime =" 86400" cookie-path =" /" cookie-domain =" example.com" cookie-secure =" true" cookie-httponly =" true " save-path =" /path/to/sessions" />
17
+ <framework : session gc-maxlifetime =" 90000" gc-probability =" 1" gc-divisor =" 108" storage-id =" session.storage.native" handler-id =" session.handler.native_file" name =" _SYMFONY" cookie-lifetime =" 86400" cookie-path =" /" cookie-domain =" example.com" cookie-secure =" true" cookie-httponly =" false " save-path =" /path/to/sessions" />
18
18
<framework : request >
19
19
<framework : format name =" csv" >
20
20
<framework : mime-type >text/csv</framework : mime-type >
Original file line number Diff line number Diff line change @@ -24,7 +24,7 @@ framework:
24
24
cookie_path : /
25
25
cookie_domain : example.com
26
26
cookie_secure : true
27
- cookie_httponly : true
27
+ cookie_httponly : false
28
28
gc_probability : 1
29
29
gc_divisor : 108
30
30
gc_maxlifetime : 90000
Original file line number Diff line number Diff line change @@ -149,7 +149,7 @@ public function testSession()
149
149
$ this ->assertEquals ('/ ' , $ options ['cookie_path ' ]);
150
150
$ this ->assertEquals ('example.com ' , $ options ['cookie_domain ' ]);
151
151
$ this ->assertTrue ($ options ['cookie_secure ' ]);
152
- $ this ->assertTrue ($ options ['cookie_httponly ' ]);
152
+ $ this ->assertFalse ($ options ['cookie_httponly ' ]);
153
153
$ this ->assertEquals (108 , $ options ['gc_divisor ' ]);
154
154
$ this ->assertEquals (1 , $ options ['gc_probability ' ]);
155
155
$ this ->assertEquals (90000 , $ options ['gc_maxlifetime ' ]);
You can’t perform that action at this time.
0 commit comments