Skip to content

Make all cookies httpOnly #17270

@ghost

Description

Summary

The matomo_lang cookie is not served as httpOnly, which was flagged by a pentest of our app. For use in high security or regulated industries, this can be a dealbreaker.

Your Environment

  • Matomo Version: 4.1.1
  • PHP Version: 7.4.7
  • Server Operating System: Amazon Linux
  • Additionally installed plugins: none

Metadata

Metadata

Assignees

Labels

EnhancementFor new feature suggestions that enhance Matomo's capabilities or add a new report, new API etc.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions