@@ -258,13 +258,15 @@ public function userInfoToLogin(?string $currentUser = null, ?string $password =
258258 $ generatedClientID = IMUtil::generateClientId ('' , $ credential );
259259 $ challenge = IMUtil::generateChallenge ();
260260 $ dbProxy ->saveChallenge ($ param ["username " ], $ challenge , $ generatedClientID , "+ " );
261- setcookie ('_im_credential_token ' ,
262- $ dbProxy ->generateCredential ($ challenge , $ generatedClientID , $ credential ),
263- time () + $ authExpired , '/ ' , "" , false , true );
264- setcookie ("_im_username_ {$ oAuthRealm }" ,
265- $ param ["username " ], time () + $ authExpired , '/ ' , "" , false , false );
266- setcookie ("_im_clientid_ {$ oAuthRealm }" ,
267- $ generatedClientID , time () + $ authExpired , '/ ' , "" , false , false );
261+ setcookie ('_im_credential_token ' , $ dbProxy ->generateCredential ($ challenge , $ generatedClientID , $ credential ),
262+ ['expires ' => time () + $ authExpired , 'path ' => '/ ' , 'domain ' => '' ,
263+ 'secure ' => false , 'httponly ' => true , 'samesite ' => 'Strict ' ]);
264+ setcookie ("_im_username_ {$ oAuthRealm }" , $ param ["username " ],
265+ ['expires ' => time () + $ authExpired , 'path ' => '/ ' , 'domain ' => '' ,
266+ 'secure ' => false , 'httponly ' => false , 'samesite ' => 'Strict ' ]);
267+ setcookie ("_im_clientid_ {$ oAuthRealm }" , $ generatedClientID ,
268+ ['expires ' => time () + $ authExpired , 'path ' => '/ ' , 'domain ' => '' ,
269+ 'secure ' => false , 'httponly ' => false , 'samesite ' => 'Strict ' ]);
268270 }
269271
270272 if ($ this ->debugMode ) {
0 commit comments