Am after some clarity on some docs: <https://docs....
# lucee
a
Am after some clarity on some docs: https://docs.lucee.org/reference/tags/application.html#attribute-sessioncookie The docs detail optional keys that can be set in that struct; but don't say what the default behaviour is if not set. CFDocs says this: https://cfdocs.org/application-cfc#p-this.sessioncookie.httpOnly Are those the correct defaults for Lucee?
z
with 5.4 they are all off be default, just create a mini app and call with curl to see the set cookie headers
or look at the test cases 😉
a
I should be able to read the docs mate. I shouldn't need to dick around creating a "mini app", or mess around trawling through source code (the latter seldom being a particularly edifying exercise, so I like to avoid it if poss). Am happy to update the docs for you if I can actually get the clarification of the answer. Can you pls clarify this:
with 5.4 they are all off be default
So that differs from cfdocs (are these the CF values? No mention of Lucee there at all): •
httpOnly
, which says it's
true
by default. Should Lucee be the opposite of CF? That's a compat break innit? •
timeout
defaults to
30 years
. But Lucee defaults to
false
, does it? •
samesite
on CF takes possible values
Strict
,
Lax
,
None
, but Lucee defaults to...
false
. Does it?
z
lucee 5 defaults samesite to "", 6.0 defaults to "lax" httponly is false in 5 and true in 6 https://luceeserver.atlassian.net/browse/LDEV-3448
moto for 6 is secure by default
a
Cool. And the current docs... they reflect the 6 behaviour yeah?
I think I read somewhere they'd been updated for 6 already?
z
docs is built from 6 and any new stuff is 6 is annotated, but when the docs web version has been edited, the improved docs take precedence
a
(askin' so I how how to update em...)
z
if you run it locally, you get a gui editor which shows both the lucee definitions and the updated web ones, otherwise you can edit a file at a time via the github icon
a
I'll just be doing it on github.
z
image.png
a
Yeah I know where it is. I linked to it in my initial comment. That's what I was reading trying to work out what the defaults were.