Including httponly in cookies
Before this gets taken down as a duplicate question, I want to say that I have spent quite some time trying to find the appropriate solutions but came up short.
So I have this .php file:
<?php
$username = $_POST["id"];
$password = $_POST["pass"];
saveLogin($username, $password);
echo "Welcome to our App " . $username;
echo "<p> </p>";
echo "Enter the sample config file to be view";
echo "<form name='view form' method='post' action='Deleteme.php'> ";
echo "<tr> <td>Filename (e.g. sampleconfig.dat):</td> ";
echo "<td><input name='configdata' type='text' size='50'></td> </tr>";
echo "<tr> <td colspan='2' align='center'><input name='btnsubmit' type='submit' value='Submit'></td> </tr>";
echo "</table> </form>";
function saveLogin($id, $pass){
$data = $id . ',' . $pass;
setcookie ("userdata", $data);
}
?>
My question is what and where do I incorporate the httponly portion to the cookie?
Any help would be greatly appreciated!
php
add a comment |
Before this gets taken down as a duplicate question, I want to say that I have spent quite some time trying to find the appropriate solutions but came up short.
So I have this .php file:
<?php
$username = $_POST["id"];
$password = $_POST["pass"];
saveLogin($username, $password);
echo "Welcome to our App " . $username;
echo "<p> </p>";
echo "Enter the sample config file to be view";
echo "<form name='view form' method='post' action='Deleteme.php'> ";
echo "<tr> <td>Filename (e.g. sampleconfig.dat):</td> ";
echo "<td><input name='configdata' type='text' size='50'></td> </tr>";
echo "<tr> <td colspan='2' align='center'><input name='btnsubmit' type='submit' value='Submit'></td> </tr>";
echo "</table> </form>";
function saveLogin($id, $pass){
$data = $id . ',' . $pass;
setcookie ("userdata", $data);
}
?>
My question is what and where do I incorporate the httponly portion to the cookie?
Any help would be greatly appreciated!
php
I'm more worried about the way you make cookies. Never ever store passwords in cookies.
– Variable
Nov 27 '18 at 18:53
This was part of a program for an assignment in which we need to find the vulnerabilities. I thought it didn't seem appropriate to store them in cookies. Sessions would be the best bet, correct?
– Stackhouse
Nov 27 '18 at 18:57
1
in that case, alright.. But it's never safe to store passwords in cookies or sessions, even if it's not an assignment.
– Variable
Nov 27 '18 at 19:00
Oh ok, that's really good to know! So what's the best way to store them?
– Stackhouse
Nov 27 '18 at 19:06
add a comment |
Before this gets taken down as a duplicate question, I want to say that I have spent quite some time trying to find the appropriate solutions but came up short.
So I have this .php file:
<?php
$username = $_POST["id"];
$password = $_POST["pass"];
saveLogin($username, $password);
echo "Welcome to our App " . $username;
echo "<p> </p>";
echo "Enter the sample config file to be view";
echo "<form name='view form' method='post' action='Deleteme.php'> ";
echo "<tr> <td>Filename (e.g. sampleconfig.dat):</td> ";
echo "<td><input name='configdata' type='text' size='50'></td> </tr>";
echo "<tr> <td colspan='2' align='center'><input name='btnsubmit' type='submit' value='Submit'></td> </tr>";
echo "</table> </form>";
function saveLogin($id, $pass){
$data = $id . ',' . $pass;
setcookie ("userdata", $data);
}
?>
My question is what and where do I incorporate the httponly portion to the cookie?
Any help would be greatly appreciated!
php
Before this gets taken down as a duplicate question, I want to say that I have spent quite some time trying to find the appropriate solutions but came up short.
So I have this .php file:
<?php
$username = $_POST["id"];
$password = $_POST["pass"];
saveLogin($username, $password);
echo "Welcome to our App " . $username;
echo "<p> </p>";
echo "Enter the sample config file to be view";
echo "<form name='view form' method='post' action='Deleteme.php'> ";
echo "<tr> <td>Filename (e.g. sampleconfig.dat):</td> ";
echo "<td><input name='configdata' type='text' size='50'></td> </tr>";
echo "<tr> <td colspan='2' align='center'><input name='btnsubmit' type='submit' value='Submit'></td> </tr>";
echo "</table> </form>";
function saveLogin($id, $pass){
$data = $id . ',' . $pass;
setcookie ("userdata", $data);
}
?>
My question is what and where do I incorporate the httponly portion to the cookie?
Any help would be greatly appreciated!
php
php
asked Nov 27 '18 at 18:44
StackhouseStackhouse
266
266
I'm more worried about the way you make cookies. Never ever store passwords in cookies.
– Variable
Nov 27 '18 at 18:53
This was part of a program for an assignment in which we need to find the vulnerabilities. I thought it didn't seem appropriate to store them in cookies. Sessions would be the best bet, correct?
– Stackhouse
Nov 27 '18 at 18:57
1
in that case, alright.. But it's never safe to store passwords in cookies or sessions, even if it's not an assignment.
– Variable
Nov 27 '18 at 19:00
Oh ok, that's really good to know! So what's the best way to store them?
– Stackhouse
Nov 27 '18 at 19:06
add a comment |
I'm more worried about the way you make cookies. Never ever store passwords in cookies.
– Variable
Nov 27 '18 at 18:53
This was part of a program for an assignment in which we need to find the vulnerabilities. I thought it didn't seem appropriate to store them in cookies. Sessions would be the best bet, correct?
– Stackhouse
Nov 27 '18 at 18:57
1
in that case, alright.. But it's never safe to store passwords in cookies or sessions, even if it's not an assignment.
– Variable
Nov 27 '18 at 19:00
Oh ok, that's really good to know! So what's the best way to store them?
– Stackhouse
Nov 27 '18 at 19:06
I'm more worried about the way you make cookies. Never ever store passwords in cookies.
– Variable
Nov 27 '18 at 18:53
I'm more worried about the way you make cookies. Never ever store passwords in cookies.
– Variable
Nov 27 '18 at 18:53
This was part of a program for an assignment in which we need to find the vulnerabilities. I thought it didn't seem appropriate to store them in cookies. Sessions would be the best bet, correct?
– Stackhouse
Nov 27 '18 at 18:57
This was part of a program for an assignment in which we need to find the vulnerabilities. I thought it didn't seem appropriate to store them in cookies. Sessions would be the best bet, correct?
– Stackhouse
Nov 27 '18 at 18:57
1
1
in that case, alright.. But it's never safe to store passwords in cookies or sessions, even if it's not an assignment.
– Variable
Nov 27 '18 at 19:00
in that case, alright.. But it's never safe to store passwords in cookies or sessions, even if it's not an assignment.
– Variable
Nov 27 '18 at 19:00
Oh ok, that's really good to know! So what's the best way to store them?
– Stackhouse
Nov 27 '18 at 19:06
Oh ok, that's really good to know! So what's the best way to store them?
– Stackhouse
Nov 27 '18 at 19:06
add a comment |
1 Answer
1
active
oldest
votes
setcookie("userdata", $data, 0, '/', '.example.com', FALSE, TRUE);
setcookie
Awesome thank you!
– Stackhouse
Nov 27 '18 at 18:59
add a comment |
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53506210%2fincluding-httponly-in-cookies%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
setcookie("userdata", $data, 0, '/', '.example.com', FALSE, TRUE);
setcookie
Awesome thank you!
– Stackhouse
Nov 27 '18 at 18:59
add a comment |
setcookie("userdata", $data, 0, '/', '.example.com', FALSE, TRUE);
setcookie
Awesome thank you!
– Stackhouse
Nov 27 '18 at 18:59
add a comment |
setcookie("userdata", $data, 0, '/', '.example.com', FALSE, TRUE);
setcookie
setcookie("userdata", $data, 0, '/', '.example.com', FALSE, TRUE);
setcookie
edited Nov 27 '18 at 18:59
answered Nov 27 '18 at 18:57
oddtwelveoddtwelve
908813
908813
Awesome thank you!
– Stackhouse
Nov 27 '18 at 18:59
add a comment |
Awesome thank you!
– Stackhouse
Nov 27 '18 at 18:59
Awesome thank you!
– Stackhouse
Nov 27 '18 at 18:59
Awesome thank you!
– Stackhouse
Nov 27 '18 at 18:59
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53506210%2fincluding-httponly-in-cookies%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
I'm more worried about the way you make cookies. Never ever store passwords in cookies.
– Variable
Nov 27 '18 at 18:53
This was part of a program for an assignment in which we need to find the vulnerabilities. I thought it didn't seem appropriate to store them in cookies. Sessions would be the best bet, correct?
– Stackhouse
Nov 27 '18 at 18:57
1
in that case, alright.. But it's never safe to store passwords in cookies or sessions, even if it's not an assignment.
– Variable
Nov 27 '18 at 19:00
Oh ok, that's really good to know! So what's the best way to store them?
– Stackhouse
Nov 27 '18 at 19:06