Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-22005

REST API: when using sessions, is_logged_in cookie is always set for top-level domain, not for site root dir

    XMLWordPrintable

Details

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: High High
    • None
    • None
    • None
    • None

    Description

      The code in eZ\Publish\Core\REST\Server\Output\ValueObjectVisitor\UserSession sets the is_logged_in cookie using "/".

      But when ez is not set up in vhost mode, the is_logged_in cookie should only be set for a path corresponding to current siteaccess, as done by legacy class ezpkernelweb.php

      Attachments

        Activity

          People

            Unassigned Unassigned
            gaetano.giunta-obsolete@ez.no Gaetano Giunta (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: