Enable secure cookies if wwwroot is set to HTTPS

Bug #843573 reported by François Marier
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Fix Released
Medium
François Marier

Bug Description

To further increase our protection against https-to-http downgrades, we should only set Secure Cookies (the ones that browsers will only send over HTTPS) when the wwwroot points to https or when a ssl proxy is enabled.

Changed in mahara:
milestone: none → 1.5.0
importance: Undecided → Medium
status: New → Triaged
Changed in mahara:
assignee: nobody → François Marier (fmarier)
Revision history for this message
François Marier (fmarier) wrote :
Changed in mahara:
status: Triaged → In Progress
Revision history for this message
Mahara Bot (dev-mahara) wrote : A change has been merged

Reviewed: https://reviews.mahara.org/844
Committed: http://gitorious.org/mahara/mahara/commit/203e12e031ab8d117289a6a38f1df75052eab09d
Submitter: Hugh Davenport (<email address hidden>)
Branch: master

commit 203e12e031ab8d117289a6a38f1df75052eab09d
Author: Francois Marier <email address hidden>
Date: Fri Nov 11 15:28:14 2011 +1300

    Use secure cookies when the site is served over HTTPS

    This prevents cookies from being stolen by tricking browsers into
    sending them unencrypted.

    Bug #843573

    Change-Id: I5dfe45e3721fc85ad2d289cea59c5ad1f4eae91b
    Signed-off-by: Francois Marier <email address hidden>

Changed in mahara:
status: In Progress → Fix Committed
summary: - Enable secure cookies is wwwroot is set to HTTPS
+ Enable secure cookies if wwwroot is set to HTTPS
Melissa Draper (melissa)
Changed in mahara:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.