session should be valid for a session
All checks were successful
mapguesser/pipeline/pr-develop This commit looks good

This commit is contained in:
Bence Pőcze 2023-05-02 13:18:37 +02:00
parent 75fad05362
commit d666593fde
Signed by: bence
GPG Key ID: DC5BD6E95A333E6D

12
web.php
View File

@ -100,22 +100,12 @@ if (isset($_COOKIE['COOKIES_CONSENT'])) {
session_set_save_handler(Container::$sessionHandler, true); session_set_save_handler(Container::$sessionHandler, true);
session_start([ session_start([
'gc_probability' => 0, // old sessions are deleted by MaintainDatabaseCommand 'gc_probability' => 0, // old sessions are deleted by MaintainDatabaseCommand
'cookie_lifetime' => 604800, 'cookie_lifetime' => 0,
'cookie_path' => '/', 'cookie_path' => '/',
'cookie_httponly' => true, 'cookie_httponly' => true,
'cookie_samesite' => 'Lax' 'cookie_samesite' => 'Lax'
]); ]);
if (isset($_COOKIE[session_name()])) {
// extend session cookie lifetime is cookie already exists
setcookie(session_name(), session_id(), [
'expires' => time() + 604800,
'path' => '/',
'httponly' => true,
'samesite' => 'Lax'
]);
}
// this is needed to handle old type of session IDs // this is needed to handle old type of session IDs
if (!Container::$sessionHandler->validateId(session_id())) { if (!Container::$sessionHandler->validateId(session_id())) {
session_regenerate_id(true); session_regenerate_id(true);