From 2a57a9577baa1dcf26637f78ac8bf9991484b099 Mon Sep 17 00:00:00 2001 From: Kevin MacMartin Date: Thu, 16 Apr 2020 13:29:42 -0400 Subject: [PATCH] Pull upstream updates into the php.ini --- php/php.ini | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/php/php.ini b/php/php.ini index d3c18fd..5bf46fa 100644 --- a/php/php.ini +++ b/php/php.ini @@ -1387,7 +1387,8 @@ session.cookie_domain = session.cookie_httponly = ; Add SameSite attribute to cookie to help mitigate Cross-Site Request Forgery (CSRF/XSRF) -; Current valid values are "Lax" or "Strict" +; Current valid values are "Strict", "Lax" or "None". When using "None", +; make sure to include the quotes, as `none` is interpreted like `false` in ini files. ; https://tools.ietf.org/html/draft-west-first-party-cookies-07 session.cookie_samesite = @@ -1423,8 +1424,8 @@ session.gc_maxlifetime = 1440 ; (see session.save_path above), then garbage collection does *not* ; happen automatically. You will need to do your own garbage ; collection through a shell script, cron entry, or some other method. -; For example, the following script would is the equivalent of -; setting session.gc_maxlifetime to 1440 (1440 seconds = 24 minutes): +; For example, the following script is the equivalent of setting +; session.gc_maxlifetime to 1440 (1440 seconds = 24 minutes): ; find /path/to/sessions -cmin +24 -type f | xargs rm ; Check HTTP Referer to invalidate externally stored URLs containing ids.