Adding config option to require 'secure' setting for all cookies- requires https.
diff --git a/application/config/config.php b/application/config/config.php
index 2a084ac..26b31e3 100644
--- a/application/config/config.php
+++ b/application/config/config.php
@@ -255,11 +255,13 @@
 | 'cookie_prefix' = Set a prefix if you need to avoid collisions
 | 'cookie_domain' = Set to .your-domain.com for site-wide cookies
 | 'cookie_path'   =  Typically will be a forward slash
+| 'cookie_secure' =  Cookies will only be set if a secure HTTPS connection exists.
 |
 */
 $config['cookie_prefix']	= "";
 $config['cookie_domain']	= "";
 $config['cookie_path']		= "/";
+$config['cookie_secure']	= FALSE;
 
 /*
 |--------------------------------------------------------------------------