Skip to content

Commit 4cd9796

Browse files
author
Yasuo Ohgaki
committed
Add session.use_strict_mode description to php.ini-*
1 parent 36122c7 commit 4cd9796

File tree

2 files changed

+16
-0
lines changed

2 files changed

+16
-0
lines changed

php.ini-development

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1398,6 +1398,14 @@ session.save_handler = files
13981398
; http://php.net/session.save-path
13991399
;session.save_path = "/tmp"
14001400

1401+
; Whether to use strict session mode.
1402+
; Strict session mode does not accept uninitialized session ID and regenerate
1403+
; session ID if browser sends uninitialized session ID. Strict mode protects
1404+
; applications from session fixation via session adoption vulnerability. It is
1405+
; disabled by default for maximum compatibility, but enabling it is encouraged.
1406+
; https://wiki.php.net/rfc/strict_sessions
1407+
session.use_strict_mode = 0
1408+
14011409
; Whether to use cookies.
14021410
; http://php.net/session.use-cookies
14031411
session.use_cookies = 1

php.ini-production

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1398,6 +1398,14 @@ session.save_handler = files
13981398
; http://php.net/session.save-path
13991399
;session.save_path = "/tmp"
14001400

1401+
; Whether to use strict session mode.
1402+
; Strict session mode does not accept uninitialized session ID and regenerate
1403+
; session ID if browser sends uninitialized session ID. Strict mode protects
1404+
; applications from session fixation via session adoption vulnerability. It is
1405+
; disabled by default for maximum compatibility, but enabling it is encouraged.
1406+
; https://wiki.php.net/rfc/strict_sessions
1407+
session.use_strict_mode = 0
1408+
14011409
; Whether to use cookies.
14021410
; http://php.net/session.use-cookies
14031411
session.use_cookies = 1

0 commit comments

Comments
 (0)