Set oc_token to httponly

remotes/origin/stable5
Lukas Reschke 14 years ago
parent 59404b5675
commit e7c9d5fe54
  1. 2
      lib/user.php

@ -476,7 +476,7 @@ class OC_User {
$secure_cookie = OC_Config::getValue("forcessl", false);
$expires = time() + OC_Config::getValue('remember_login_cookie_lifetime', 60*60*24*15);
setcookie("oc_username", $username, $expires, '', '', $secure_cookie);
setcookie("oc_token", $token, $expires, '', '', $secure_cookie);
setcookie("oc_token", $token, $expires, '', '', $secure_cookie, true);
setcookie("oc_remember_login", true, $expires, '', '', $secure_cookie);
}

Loading…
Cancel
Save