summaryrefslogtreecommitdiff
path: root/php.ini-production
diff options
context:
space:
mode:
authorNikita Popov <nikita.ppv@gmail.com>2020-03-18 15:59:30 +0100
committerNikita Popov <nikita.ppv@gmail.com>2020-03-18 15:59:30 +0100
commitc00cce3229515eacdb1680f39132ed3ca09cc205 (patch)
tree1264ddde6221f871954e97ee672522111ae26063 /php.ini-production
parentb114e3d953bb1d27d3686d3dc2274f4f5b9154fe (diff)
downloadphp-git-c00cce3229515eacdb1680f39132ed3ca09cc205.tar.gz
Clarify session.cookie_samesite="None"
Diffstat (limited to 'php.ini-production')
-rw-r--r--php.ini-production3
1 files changed, 2 insertions, 1 deletions
diff --git a/php.ini-production b/php.ini-production
index 5a68647eca..ee1ff0731d 100644
--- a/php.ini-production
+++ b/php.ini-production
@@ -1415,7 +1415,8 @@ session.cookie_domain =
session.cookie_httponly =
; Add SameSite attribute to cookie to help mitigate Cross-Site Request Forgery (CSRF/XSRF)
-; Current valid values are "Lax" or "Strict"
+; Current valid values are "Strict", "Lax" or "None". When using "None",
+; make sure to include the quotes, as `none` is interpreted like `false` in ini files.
; https://tools.ietf.org/html/draft-west-first-party-cookies-07
session.cookie_samesite =