// Ensure session cookies are sent only over HTTPS and inaccessible via client-side scripts. ini_set('session.cookie_secure', 1); ini_set('session.cookie_httponly', 1); // Optional: Set a strict SameSite policy to mitigate CSRF (modern browsers) // 'Lax' is often a good default, 'Strict' is more secure but can impact UX session_set_cookie_params([ 'lifetime' => 0, // Session cookie 'path' => '/', 'domain' => '.yourdomain.com', // Replace with your domain 'secure' => true, // Only send over HTTPS 'httponly' => true, // Not accessible via JavaScript 'samesite' => 'Lax' // Or 'Strict' ]); session_start(); // Your session-related code