PR-5.1-dev Pending

User tests: Successful: Unsuccessful:

avatar Denitz
Denitz
23 Jul 2024

Pull request for issue

#43309

Summary of Changes

Thanks to #37777 the cookie options with cookie_domain and cookie_path global config settings are not applied in administrator and site sessions.

This blocks session sharing between i.e. www and non-www domains or subdmains.

Testing Instructions

Edit global configuration and change Cookie Domain to .your-site.com - note leading dot.

If you have Joomla installation in a subfolder, try to change Cookie Path to /subfolder.

Actual result BEFORE applying this Pull Request

Session cookie is still using the current domain and / path

Expected result AFTER applying this Pull Request

Session cookie is using the domain and path from global config.

Link to documentations

Please select:

  • Documentation link for docs.joomla.org:

  • No documentation changes for docs.joomla.org needed

  • Pull Request link for manual.joomla.org:

  • No documentation changes for manual.joomla.org needed

avatar Denitz Denitz - open - 23 Jul 2024
avatar Denitz Denitz - change - 23 Jul 2024
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 23 Jul 2024
Category Libraries
avatar Denitz Denitz - change - 23 Jul 2024
The description was changed
avatar Denitz Denitz - edited - 23 Jul 2024
avatar Quy
Quy - comment - 23 Jul 2024
avatar rdeutz rdeutz - change - 30 Jul 2024
Labels Added: PR-5.1-dev
avatar Quy Quy - change - 5 Aug 2024
Status Pending Closed
Closed_Date 0000-00-00 00:00:00 2024-08-05 12:55:41
Closed_By Quy
avatar Quy
Quy - comment - 5 Aug 2024

Closing in favour of #43882. Thank you!

avatar Quy Quy - close - 5 Aug 2024

Add a Comment

Login with GitHub to post a comment