Skip to content
Snippets Groups Projects
Commit df5d307e authored by Gerrit Uitslag's avatar Gerrit Uitslag
Browse files

add cookie secure parameter to cookies set by javascript

parent 75e4dd8a
No related branches found
No related tags found
No related merge requests found
...@@ -86,16 +86,20 @@ function js_out(){ ...@@ -86,16 +86,20 @@ function js_out(){
// start output buffering and build the script // start output buffering and build the script
ob_start(); ob_start();
$json = new JSON();
// add some global variables // add some global variables
print "var DOKU_BASE = '".DOKU_BASE."';"; print "var DOKU_BASE = '".DOKU_BASE."';";
print "var DOKU_TPL = '".tpl_basedir()."';"; print "var DOKU_TPL = '".tpl_basedir()."';";
print "var DOKU_COOKIEPATH = '" . (empty($conf['cookiedir']) ? DOKU_REL : $conf['cookiedir']) . "';"; print "var DOKU_COOKIE_PARAM = " . $json->encode(
array(
'path' => empty($conf['cookiedir']) ? DOKU_REL : $conf['cookiedir'],
'secure' => $conf['securecookie'] && is_ssl()
)).";";
// FIXME: Move those to JSINFO // FIXME: Move those to JSINFO
print "var DOKU_UHN = ".((int) useHeading('navigation')).";"; print "var DOKU_UHN = ".((int) useHeading('navigation')).";";
print "var DOKU_UHC = ".((int) useHeading('content')).";"; print "var DOKU_UHC = ".((int) useHeading('content')).";";
// load JS specific translations // load JS specific translations
$json = new JSON();
$lang['js']['plugins'] = js_pluginstrings(); $lang['js']['plugins'] = js_pluginstrings();
$templatestrings = js_templatestrings(); $templatestrings = js_templatestrings();
if(!empty($templatestrings)) { if(!empty($templatestrings)) {
......
...@@ -30,7 +30,7 @@ var DokuCookie = { ...@@ -30,7 +30,7 @@ var DokuCookie = {
text.push(encodeURIComponent(key)+'#'+encodeURIComponent(val)); text.push(encodeURIComponent(key)+'#'+encodeURIComponent(val));
} }
}); });
jQuery.cookie(this.name, text.join('#'), {expires: 365, path: DOKU_COOKIEPATH}); jQuery.cookie(this.name, text.join('#'), {expires: 365, path: DOKU_COOKIE_PARAM.path, secure: DOKU_COOKIE_PARAM.secure});
}, },
/** /**
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment