blob: d4ee141bbb131c978322bdc326beb42348da6146 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
|
<?php
// Shared session bootstrap. Must be included before any output.
// Security headers (CSP, HSTS, nosniff, Referrer-Policy, Permissions-Policy)
// are owned by nginx — do not re-emit them here (browsers can conflict on
// duplicate policies).
if (session_status() !== PHP_SESSION_ACTIVE) {
session_set_cookie_params([
'lifetime' => 0,
'path' => '/',
'secure' => true,
'httponly' => true,
'samesite' => 'Lax',
]);
session_start();
}
|