Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-55490

cookiehttponly should default to on

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Duplicate
    • Icon: Minor Minor
    • None
    • 3.2
    • Administration
    • None
    • MOODLE_32_STABLE

      Moodle's default security settings should have better defaults, unless there is a compelling reason not too.

      I think it too should be on, there is some discussion around maybe parts of moodle which need it and possible some issues with scorm or flash content not working with it. But I haven't ever seen first hand instances of it breaking so don't know.

      With cookiehttponly on, access to cookies moodle sets can only be accessed via http requests. This helps prevent some cross site scripting (XSS) attacks

            Unassigned Unassigned
            brendanheywood Brendan Heywood
            Votes:
            1 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.