summaryrefslogtreecommitdiff
path: root/php.ini-development
diff options
context:
space:
mode:
authorYasuo Ohgaki <yohgaki@php.net>2013-08-20 18:30:30 +0900
committerYasuo Ohgaki <yohgaki@php.net>2013-08-20 18:30:30 +0900
commit4cd9796be78bfb1cc88b5ed71cbd61e56937b8e7 (patch)
tree16f50e26dd749e9d720aa7057e1ebbf105d70135 /php.ini-development
parent36122c74a200db65cfa815d183716e38587c4c85 (diff)
downloadphp-git-4cd9796be78bfb1cc88b5ed71cbd61e56937b8e7.tar.gz
Add session.use_strict_mode description to php.ini-*
Diffstat (limited to 'php.ini-development')
-rw-r--r--php.ini-development8
1 files changed, 8 insertions, 0 deletions
diff --git a/php.ini-development b/php.ini-development
index 7197dae6fc..43ab1de26a 100644
--- a/php.ini-development
+++ b/php.ini-development
@@ -1398,6 +1398,14 @@ session.save_handler = files
; http://php.net/session.save-path
;session.save_path = "/tmp"
+; Whether to use strict session mode.
+; Strict session mode does not accept uninitialized session ID and regenerate
+; session ID if browser sends uninitialized session ID. Strict mode protects
+; applications from session fixation via session adoption vulnerability. It is
+; disabled by default for maximum compatibility, but enabling it is encouraged.
+; https://wiki.php.net/rfc/strict_sessions
+session.use_strict_mode = 0
+
; Whether to use cookies.
; http://php.net/session.use-cookies
session.use_cookies = 1