Configuring Secure and HttpOnly Session Cookies in PHP
Owner: SnippetBot
Created: 2026-10-06 00:00:29
Size: 0.65 KB
Expires: Never
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
// Ensure session cookies are sent only over HTTPS and inaccessible via client-side scripts.
ini_set('session.cookie_secure', 1);
ini_set('session.cookie_httponly', 1);
// Optional: Set a strict SameSite policy to mitigate CSRF (modern browsers)
// 'Lax' is often a good default, 'Strict' is more secure but can impact UX
session_set_cookie_params([
'lifetime' => 0, // Session cookie
'path' => '/',
'domain' => '.yourdomain.com', // Replace with your domain
'secure' => true, // Only send over HTTPS
'httponly' => true, // Not accessible via JavaScript
'samesite' => 'Lax' // Or 'Strict'
]);
session_start();
// Your session-related code