Menu

#4864 Tried to set secure cookie on non-secure connection

4.4.3
invalid
None
Normal
2015-07-10
2015-04-21
No

GET /pma/navigation.php? ..

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0
..
X-Powered-By: PHP/5.4.39-0+deb7u2
Last-Modified: Mon, 20 Apr 2015 11:51:18 GMT
Set-Cookie: phpMyAdmin=**; path=/pma/; secure; HttpOnly

Discussion

  • Olaf van der Spek

    _SERVER["HTTPS"] == 'on' even though the request is non-https.

     
  • Olaf van der Spek

    Why can't pMA use relative URLs?

     
  • Madhura Jayaratne

    • assigned_to: Madhura Jayaratne
     
  • Madhura Jayaratne

    Can you describe the steps to generate this bug.
    Do you see all the requests non-https or just the /pma/navigation.php?... (Full request path will be useful here)

     
  • Madhura Jayaratne

    • status: open --> pending
     
  • Olaf van der Spek

    It's probably a bug in Lighttpd.

     
  • Madhura Jayaratne

    • status: pending --> invalid