RFC: Secure Session Configuration Defaults

Project Governance
Author
Jorg Sowa
Target
8.6
Three ini settings in PHP's session extension have security implications but ship with defaults that leave applications unnecessarily exposed. This RFC proposes...

Change session.use_strict_mode default to 1?

Overall Results

Yes
No
Abstain
Yes
27 Votes (100%)
No
0 Votes (0%)
Abstain
0 Votes (0%)

Voting Timeline

Dates based on UTC

Voting Breakdown

Change session.cookie_httponly default to 1?

Overall Results

Yes
No
Abstain
Yes
26 Votes (96%)
No
0 Votes (0%)
Abstain
1 Votes (4%)

Voting Timeline

Dates based on UTC

Voting Breakdown

Change session.cookie_samesite default to Lax?

Overall Results

Yes
No
Abstain
Yes
26 Votes (100%)
No
0 Votes (0%)
Abstain
0 Votes (0%)

Voting Timeline

Dates based on UTC

Voting Breakdown