Session Cookie without HttpOnly flag set

apache, javascript, php, security

Solution

You can either change settings in php.ini, or via `ini_set()` calls to change `session.cookie_secure` and `session.cookie_httponly` values to `true`.

Alternately, you can use `session_set_cookie_params()` before starting your session to get the effect you are looking for.

https://www.php.net/manual/en/function.session-set-cookie-params.php

Problem

I have joust built a website with a login system. After I've just got ready I have scanned it with Acunetix, but I got the following message: Session Cookie without HttpOnly flag set Session Cookie without Secure flag set (i guess this is only if I have SSL connection) So my question would be, that how can I set HttpOnly flag for all my Session data? I'm just using sessions when I log in the users. I'm giving them a session with their userID number and than I'm getting data using that userID. Is there any simple way that I can set ALL of the session HTTPOnly and secure them, so noone can touch them?

Original source