Explorar o código

Fix bug: Session cookie domain

If the web domain is != mail domain, the session cookie is set to the wrong domain.
Dennis Neufeld %!s(int64=8) %!d(string=hai) anos
pai
achega
0d3d9b8c15
Modificáronse 1 ficheiros con 1 adicións e 1 borrados
  1. 1 1
      data/web/inc/sessions.inc.php

+ 1 - 1
data/web/inc/sessions.inc.php

@@ -13,7 +13,7 @@ elseif (isset($_SERVER['HTTPS'])) {
 else {
   $IS_HTTPS = false;
 }
-session_set_cookie_params($GLOBALS['SESSION_LIFETIME'], '/', $_SERVER['SERVER_NAME'], $IS_HTTPS, true);
+session_set_cookie_params($GLOBALS['SESSION_LIFETIME'], '/', '', $IS_HTTPS, true);
 session_start();
 if (!isset($_SESSION['CSRF']['TOKEN'])) {
   $_SESSION['CSRF']['TOKEN'] = bin2hex(random_bytes(32));