Details
-
Bug
-
Resolution: Fixed
-
High
-
None
-
None
-
None
-
None
Description
The code in eZ\Publish\Core\REST\Server\Output\ValueObjectVisitor\UserSession sets the is_logged_in cookie using "/".
But when ez is not set up in vhost mode, the is_logged_in cookie should only be set for a path corresponding to current siteaccess, as done by legacy class ezpkernelweb.php