Change Context::isAlwaysSSL() to config('session.use_ssl_cookies')

- Main session cookie is httpOnly if use_ssl is true
- SSO cookie is always httpOnly
This commit is contained in:
Kijin Sung 2018-08-06 01:23:22 +09:00
parent 2c9bb88a14
commit a49f2f5f06
8 changed files with 18 additions and 35 deletions

View file

@ -73,7 +73,7 @@ class Mobile
$uatype = $uahash . ':' . (self::$_ismobile ? '1' : '0');
if ($cookie !== $uatype)
{
setcookie('rx_uatype', $uatype, 0, null, null, Context::isAlwaysSSL());
setcookie('rx_uatype', $uatype, 0, null, null, !!config('session.use_ssl_cookies'));
$_COOKIE['rx_uatype'] = $uatype;
}