Both of these flags can be set either by defining the appropriate constant in the server’s php.ini file or at runtime through session_set_cookie_params before session_start() is invoked by the application.


this should be done everywhere now that https is general