fix configuration.php setting name to enable samesite none header option

pull/4041/head
juan-cortizas-ponte 4 years ago
parent 10fda86296
commit 3dab673026
  1. 2
      main/inc/lib/chamilo_session.class.php
  2. 10
      main/install/configuration.dist.php

@ -87,7 +87,7 @@ class ChamiloSession extends System\Session
//session ID in the cookie is only readable by the server
ini_set('session.cookie_httponly', 1);
if (api_get_configuration_value('allow_session_samesite_none_cookie_parameter')) {
if (api_get_configuration_value('security_session_cookie_samesite_none')) {
if (PHP_VERSION_ID < 70300) {
$sessionCookieParams = session_get_cookie_params();
session_set_cookie_params($sessionCookieParams['lifetime'], '/; samesite=None',

@ -558,6 +558,11 @@ ALTER TABLE sys_announcement ADD COLUMN visible_boss INT DEFAULT 0;
// information the browser includes with navigation away from a document
// and should be set by all sites.
//$_configuration['security_referrer_policy'] = 'origin-when-cross-origin';
//
// Enable samesite:None parameter for session cookie.
// More info: https://www.chromium.org/updates/same-site
// Also: https://developers.google.com/search/blog/2020/01/get-ready-for-new-samesitenone-secure
//$_configuration['security_session_cookie_samesite_none'] = false;
// ------ HTTP headers security section ends here
//
// ------ Survey configuration settings
@ -2009,11 +2014,6 @@ VALUES (21, 13, 'send_notification_at_a_specific_date', 'Send notification at a
// Overwrites the app/config/auth.conf.php settings
//$_configuration['extldap_config'] = ['host' => '', 'port' => ''];
// Enable samesite:None parameter for session cookie.
// More info: https://www.chromium.org/updates/same-site
// Also: https://developers.google.com/search/blog/2020/01/get-ready-for-new-samesitenone-secure
//$_configuration['allow_session_samesite_none_cookie_parameter'] = false;
// KEEP THIS AT THE END
// -------- Custom DB changes
// Add user activation by confirmation email

Loading…
Cancel
Save