[SECURITY] Make InstallTool session cookie HTTP-only 03/59103/2
authorAndreas Wolf <dev@a-w.io>
Tue, 11 Dec 2018 09:57:18 +0000 (10:57 +0100)
committerOliver Hader <oliver.hader@typo3.org>
Tue, 11 Dec 2018 09:57:20 +0000 (10:57 +0100)
commit13328b0f74ac589a20b021db814dfa672581c26a
tree08e7a20903bf2d71a3e860ecb613248caab3fa42
parent1c85fe70269e2ff8ecf0b6d5f16550c6cd0ddc78
[SECURITY] Make InstallTool session cookie HTTP-only

Resolves: #86955
Releases: master, 8.7, 7.6
Security-Commit: d251175e031aaa9943f93f5e5297f5490b99e513
Security-Bulletin: TYPO3-CORE-SA-2018-009
Change-Id: Ia50cac61ee2d649e98cba2102162c1360487bb20
Reviewed-on: https://review.typo3.org/59103
Reviewed-by: Oliver Hader <oliver.hader@typo3.org>
Tested-by: Oliver Hader <oliver.hader@typo3.org>
typo3/sysext/install/Classes/Service/SessionService.php