Jump to content
scott001

Insecure Cookies Warnings - Non-SSL Cookies

Recommended Posts

I am still getting these warnings. The adserver's cookies are not secure https:

The Secure directive

By adding the Secure instruction in the Set-Cookie HTTP header, the server informs the browser that it is allowed to transmit the cookie over secure connection only. Read this blog post to learn more.

Caution: Ensure that the HTTP to HTTPS redirect is activated on your website. Otherwise, the Secure cookie may not be sent on HTTP request.

The following Cookies are not secure, you should add the Secure instruction in the Set-Cookie HTTP header:

EXAMPLES:

  • set-cookie: spcsrf=a7926253af246ee7f09f04062fcde42d; Expires=Thu, 25-Apr-19 19:03:00 GMT; Path=/; HttpOnly; SameSite=Strict
  • set-cookie: UTGv2=D-h4f4bae1c99aeac150608db7df7d860a3547; Expires=Fri, 24-Apr-20 17:03:00 GMT; Path=/
  • set-cookie: OAID=a32d8dd64ecb4a95ef3092870b2080ea; expires=Fri, 24-Apr-2020 17:03:00 GMT; Max-Age=31536000; path=/
  • set-cookie: _OXLIA[2202]=pqj0p0-326; expires=Sat, 25-May-2019 17:03:00 GMT; Max-Age=2592000; path=/

Anyone know how to fix this? The answer probably lies in this file:

lib/pear/HTTP/Request.php

Share this post


Link to post
Share on other sites

I don't have my domain in the conf cookie setting...does this matter? If I add it should I include www?

[openads]
installed=1
requireSSL=1
sslPort=443
language=en

[max]
requireSSL=1
sslPort=443

[database]
type=mysqli
host=localhost
port=3306

[cookie]
permCookieSeconds=31536000
maxCookieSize=2048
domain=
viewerIdDomain=
 

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




×
×
  • Create New...