According to Mozilla best-practices (see https://observatory.mozilla.org and https://infosec.mozilla.org/guidelines/web_security#cookies ) session cookies should be created with the HttpOnly flag. This prevents XSS vulnerabilities. This PHPSESSID cookie is still sent over ajax calls (it just prevents JS to access it) so it does not break any usage
Name |
Last commit
|
Last update |
---|---|---|
.. | ||
ajax | Loading commit data... | |
app | Loading commit data... | |
db | Loading commit data... | |
lang | Loading commit data... | |
pages | Loading commit data... | |
plugins | Loading commit data... | |
util | Loading commit data... | |
vendor | Loading commit data... | |
qa-ajax.php | Loading commit data... | |
qa-base.php | Loading commit data... | |
qa-blob.php | Loading commit data... | |
qa-check-lang.php | Loading commit data... | |
qa-db.php | Loading commit data... | |
qa-feed.php | Loading commit data... | |
qa-image.php | Loading commit data... | |
qa-index.php | Loading commit data... | |
qa-install.php | Loading commit data... | |
qa-page-not-found.php | Loading commit data... | |
qa-page.php | Loading commit data... | |
qa-theme-base.php | Loading commit data... | |
qa-url-test.php | Loading commit data... |