]> git.mjollnir.org Git - moodle.git/commitdiff
MDL-18137 all cookies now secure if configured to be
authorskodak <skodak>
Sat, 7 Feb 2009 22:41:59 +0000 (22:41 +0000)
committerskodak <skodak>
Sat, 7 Feb 2009 22:41:59 +0000 (22:41 +0000)
lib/sessionlib.php

index 9ab764474a034a0d97b31428ddf6bae32daeb230..d7bb00b1d0b1b93714758e1c554223aeb88cd578 100644 (file)
@@ -738,9 +738,8 @@ function set_moodle_cookie($thing) {
     $days = 60;
     $seconds = DAYSECS*$days;
 
-    // no need to set secure or http cookie only here - it is not secret
-    setcookie($cookiename, '', time() - HOURSECS, $CFG->sessioncookiepath, $CFG->sessioncookiedomain);
-    setcookie($cookiename, rc4encrypt($thing), time()+$seconds, $CFG->sessioncookiepath, $CFG->sessioncookiedomain);
+    setcookie($cookiename, '', time() - HOURSECS, $CFG->sessioncookiepath, $CFG->sessioncookiedomain, $CFG->cookiesecure, $CFG->cookiehttponly);
+    setcookie($cookiename, rc4encrypt($thing), time()+$seconds, $CFG->sessioncookiepath, $CFG->sessioncookiedomain, $CFG->cookiesecure, $CFG->cookiehttponly);
 }
 
 /**