Sessions Options Are All Set to False Upon Install

Description

This is the same as with OSC. All session options are set to false upon install. Its not "broken" but not ideal.

Title Value
Session Directory /tmp
Force Cookie Use False
Check SSL Session ID False
Check User Agent False
Check IP Address False
Prevent Spider Sessions False
Recreate Session False

I think the best practice is at minimum to set as follows

Title Value
Session Directory /tmp
Force Cookie Use False
Check SSL Session ID False
Check User Agent False
Check IP Address False
Prevent Spider Sessions True
Recreate Session True

Environment

None

Steps to reproduce

Install OSCmax on a new server.
Login to the shopping cart admin tool
Navigate to Administrator/Sessions

Note by default all session variables are false

Status

Assignee

Giles Marshall

Reporter

llamma

Labels

None

Severity

Tweak

Components

Fix versions

Affects versions

v2.5.0

Priority

Configure