I read this has been an issue in the past, but i just cant get around it. It is trustwave. They are flagging the limesurvey for using nonssl cookies. I have modified the config.php
With secure ===> true
i set:
http only is set to true then reboot - no change;
httponly set to false ; then reboot - no change
But it does not seem to help Trustwave detects insecure cookies.
I have more information from another scanning tool. It seems that secure cookies in the config.php is being applied. But another issue came up. see attached.
Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member. -
Professional support
-
Plugins, theme and development
. I don't answer to private message.