summaryrefslogtreecommitdiffstats
path: root/Bugzilla
diff options
context:
space:
mode:
Diffstat (limited to 'Bugzilla')
-rw-r--r--Bugzilla/Auth/Persist/Cookie.pm9
-rw-r--r--Bugzilla/Install/Requirements.pm3
2 files changed, 8 insertions, 4 deletions
diff --git a/Bugzilla/Auth/Persist/Cookie.pm b/Bugzilla/Auth/Persist/Cookie.pm
index 3faa892ae..4928068e5 100644
--- a/Bugzilla/Auth/Persist/Cookie.pm
+++ b/Bugzilla/Auth/Persist/Cookie.pm
@@ -76,17 +76,20 @@ sub persist_login {
{
$cgi->send_cookie(-name => 'Bugzilla_login',
-value => $user->id,
+ -httponly => 1,
-expires => 'Fri, 01-Jan-2038 00:00:00 GMT');
$cgi->send_cookie(-name => 'Bugzilla_logincookie',
-value => $login_cookie,
+ -httponly => 1,
-expires => 'Fri, 01-Jan-2038 00:00:00 GMT');
-
}
else {
$cgi->send_cookie(-name => 'Bugzilla_login',
- -value => $user->id);
+ -value => $user->id,
+ -httponly => 1);
$cgi->send_cookie(-name => 'Bugzilla_logincookie',
- -value => $login_cookie);
+ -value => $login_cookie,
+ -httponly => 1);
}
}
diff --git a/Bugzilla/Install/Requirements.pm b/Bugzilla/Install/Requirements.pm
index fd3dcf589..2216d963d 100644
--- a/Bugzilla/Install/Requirements.pm
+++ b/Bugzilla/Install/Requirements.pm
@@ -61,7 +61,8 @@ sub REQUIRED_MODULES {
module => 'CGI',
# Perl 5.10 requires CGI 3.33 due to a taint issue when
# uploading attachments, see bug 416382.
- version => (vers_cmp($perl_ver, '5.10') > -1) ? '3.33' : '2.93'
+ # Require CGI 3.21 for -httponly support, see bug 368502.
+ version => (vers_cmp($perl_ver, '5.10') > -1) ? '3.33' : '3.21'
},
{
package => 'TimeDate',