[SECURITY] Make InstallTool session cookie HTTP-only 87/59087/2
authorOliver Hader <oliver@typo3.org>
Tue, 11 Dec 2018 09:55:23 +0000 (10:55 +0100)
committerOliver Hader <oliver.hader@typo3.org>
Tue, 11 Dec 2018 09:55:25 +0000 (10:55 +0100)
commit918e50e4d20d88c7e40ad3bb134267d07706b0b1
tree3e9c4fffbefc75799f9173d5a280a513b230d6a1
parent373bec5d7d415f0764ebbadc7970610dc26da068
[SECURITY] Make InstallTool session cookie HTTP-only

Resolves: #86955
Releases: master, 8.7, 7.6, 6.2
Security-Commit: d554a3f8d40df0e9019b89f7bb4f8fec85e15331
Security-Bulletin: TYPO3-CORE-SA-2018-009
Change-Id: I6d74cc2bc2ba876986887564bb48eb5d5d8ae3ac
Reviewed-on: https://review.typo3.org/59087
Reviewed-by: Oliver Hader <oliver.hader@typo3.org>
Tested-by: Oliver Hader <oliver.hader@typo3.org>
typo3/sysext/install/Classes/Service/SessionService.php