Enable secure for JWT-cookie
				
					
				
			This commit is contained in:
		| @@ -106,7 +106,7 @@ function storeToken (string $secureToken, string $qualifiedUsername, string $htt | ||||
| 		//   This might seem backwards, but relying on $_SERVER directly allows spoofed values with potential security risks | ||||
| 		return (strlen($value) > strlen($httpHost)) ? false : (0 === substr_compare($httpHost, $value, -strlen($value))); | ||||
| 	}))[0]; | ||||
| 	if ($cookieDomain && setcookie('JWT', $secureToken, (time() + $settings->Session['Duration']), '/', '.' . $cookieDomain)) { | ||||
| 	if ($cookieDomain && setcookie('JWT', $secureToken, (time() + $settings->Session['Duration']), '/', '.' . $cookieDomain, TRUE)) { | ||||
| 		return ['status' => 'Success']; | ||||
| 	} else { | ||||
| 		return ['status' => 'Fail', 'reason' => 'Unable to store cookie(s)']; | ||||
|   | ||||
		Reference in New Issue
	
	Block a user