From c9b109601af001e364b664cb86c2ca9532350bbe Mon Sep 17 00:00:00 2001 From: Jeroen De Meerleer Date: Mon, 31 Jan 2022 15:24:41 +0100 Subject: [PATCH] ENHANCEMENT: added security hardening --- bootstrap.php | 1 - lib/Framework/Kernel.php | 6 ++++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/bootstrap.php b/bootstrap.php index b5d4881..9711f53 100644 --- a/bootstrap.php +++ b/bootstrap.php @@ -1,6 +1,5 @@ router = new Router(); $this->router->parseRoutes($this->getConfigDir(), 'routes.yaml'); $request = $this->parseRequest(); + if($request->isSecure()) { + ini_set('session.cookie_httponly', true); + ini_set('session.cookie_secure', true); + } + + session_start(); return $this->router->route($request, $this); }