Hi,
Playing with hardening a little, and implemented samesite flag within a cookie, or at least tried to.
Code like:
session_set_cookie_params(0, "/; SameSite=Strict", "domain.com", true, true);
$params = session_get_cookie_params();
session_start();
setcookie("PHPSESSID", session_id(), $params["lifetime"], $params["path"], $params["domain"], $params["secure"], $params["httponly"]);
Warning:
PHP Warning: Cookie paths cannot contain any of the following ',; \t\r\n\013\014' in /homepages/39/d582945504/htdocs/portal-x/inc/cookies.php on line 21
Not sure if it's a huge deal to just leave that out..