php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #55002 setcookie httponly parameter documentation problem
Submitted: 2011-06-06 19:59 UTC Modified: 2011-07-01 19:05 UTC
From: fsb at thefsb dot org Assigned: frozenfire (profile)
Status: Closed Package: Documentation problem
PHP Version: 5.3.6 OS: All
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: fsb at thefsb dot org
New email:
PHP Version: OS:

 

 [2011-06-06 19:59 UTC] fsb at thefsb dot org
Description:
------------
---
From manual page: http://www.php.net/function.setcookie#Parameters
---

In the description of @param httponly, the sentence "This setting can 
effectively 
help to reduce identity theft through XSS attacks (although it is not supported 
by 
all browsers)," is at best controversial and perhaps even misleading. It has 
been 
widely discussed so I let you research it with Google.

---
Suggested remedy
---

I would delete the sentence altogether and replace it with a simple reference to 
RFC 6265 http://www.rfc-editor.org/rfc/rfc6265.txt  This keeps you out of the 
argument.

Alternatively, use weasel words. Try: "This setting may help to reduce 
identity..."




Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-07-01 19:05 UTC] frozenfire@php.net
Automatic comment from SVN on behalf of frozenfire
Revision: http://svn.php.net/viewvc/?view=revision&revision=312787
Log: Added weasel words to httponly parameter, as per bug #55002.
 [2011-07-01 19:05 UTC] frozenfire@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: frozenfire
 [2011-07-01 19:05 UTC] frozenfire@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.


 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Fri Oct 09 22:00:02 2026 UTC