session.cookie_samesite
INI • INI default value changed in 8.6
Session: session.cookie_samesite — Add SameSite attribute to cookie to help mitigate Cross-Site Request Forgery (CSRF/XSRF) Current valid values are "Strict", "Lax" or "None". When using "None", make sure to include the quotes, as none is interpreted like false in ini files. https://tools.ietf.org/html/draft-west-first-party-cookies-07
| Default value | "Lax" |
| Development value | "Lax" |
| Production value | "Lax" |
Modifiability: INI_ALL - The session.cookie_samesite INI directive can be configured anywhere, including php.ini files, ini_set calls, Apache .htaccess files, per-directory .ini files, etc.
[Session]
session.cookie_samesite = "Lax" Changes to the session.cookie_samesite INI
PHP 8.6
- INI directive default value set to
Lax
PHP 7.3
- INI directive added
session.cookie_samesite INI Availability
session.cookie_samesite INI Availability| PHP Version | Availability |
|---|---|
| PHP 8.6Upcoming Release | Yes |
| PHP 8.5Supported (Latest) | Yes |
| PHP 8.4Supported | Yes |
| PHP 8.3Security-Fixes Only | Yes |
| PHP 8.2Security-Fixes Only | Yes |
| PHP 8.1Unsupported | Yes |
| PHP 8.0Unsupported | Yes |
| PHP 7.4Unsupported | Yes |
| PHP 7.3Unsupported | Yes |
| PHP 7.2Unsupported | No |
| PHP 7.1Unsupported | No |
| PHP 7.0Unsupported | No |
| PHP 5.6Unsupported | No |
| PHP 5.5Unsupported | No |
| PHP 5.4Unsupported | No |
| PHP 5.3Unsupported | No |