No Code Attached Yet
avatar lancedouglas1
lancedouglas1
18 Apr 2024

Steps to reproduce the issue

  • Install Joomla 5.1.0
  • Configure the global->site->cookie_domain to .yourdomain (including the preceding dot).
  • Save, logout, launch incognito, different browser, or clear cache and restart browser to ensure you're getting the latest cookie.
  • Visit and login to the frontend or admin section of website.
  • Check the cookies in developer tools.

Expected result

  • Joomla session cookie with domain= .yourdomain (including preceding dot)
  • joomla_user_state cookie with domain= .yourdomain (including preceding dot)

Actual result

  • Joomla session cookie with domain= yourdomain (without preceding dot)
  • joomla_user_state cookie with domain= .yourdomain (including preceding dot)

System information (as much as possible)

Setting	Value
PHP Built On	Linux SBS-dev-1 6.5.0-1018-azure #19~22.04.2-Ubuntu SMP Thu Mar 21 16:45:46 UTC 2024 x86_64
Database Type	mysql
Database Version	10.6.16-MariaDB-0ubuntu0.22.04.1
Database Collation	utf8mb4_general_ci
Database Connection Collation	utf8mb4_general_ci
Database Connection Encryption	None
Database Server Supports Connection Encryption	No
PHP Version	8.3.6
Web Server	nginx/1.18.0
WebServer to PHP Interface	fpm-fcgi
Joomla! Version	Joomla! 5.1.0 Stable [ Kudumisha ] 16-April-2024 16:00 GMT
Joomla Backward Compatibility Plugin	Enabled (classes_aliases:"1", es5_assets:"1")
User Agent	Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36

Additional comments

  • testing in both safari and chrome
  • tested with both shared sessions on and off
  • image showing example attached
    Screenshot 2024-04-18 at 12 12 05
avatar lancedouglas1 lancedouglas1 - open - 18 Apr 2024
avatar joomla-cms-bot joomla-cms-bot - change - 18 Apr 2024
Labels Added: No Code Attached Yet
avatar joomla-cms-bot joomla-cms-bot - labeled - 18 Apr 2024
avatar lancedouglas1 lancedouglas1 - change - 18 Apr 2024
Title
cookie domain incorrect for session cookie only
[5.1] cookie domain incorrect for session cookie only
avatar lancedouglas1 lancedouglas1 - edited - 18 Apr 2024
avatar richard67 richard67 - change - 23 Jul 2024
Status New Closed
Closed_Date 0000-00-00 00:00:00 2024-07-23 16:59:02
Closed_By richard67
avatar richard67 richard67 - close - 23 Jul 2024
avatar richard67
richard67 - comment - 23 Jul 2024

Closing as having a pull request. Please test #43834 . Thanks in advance.

Add a Comment

Login with GitHub to post a comment