• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Cookies and secure attribute

AgentZap

Senior member
If your website does all communication over SSL, but your cookies don't have the secure attribute set on them would they be sent over SSL anyway or would they instead be sent plaintext?
 
Cookies are transmitted in the headers during web requests, so if you are using SSL your cookies will be encrypted in transit just like the rest of the data.

edit: It's worth mentioning that the SecureFlag forces the cookies to only be sent over SSL. I don't know what kind of behavior you would see on a non-ssl session with that flag set though.
 
Back
Top