Manual:$wgCookieSecure/en

Details
Whether cookies are secured ($Secure attribute of cookies, see section 4.1.2.5 in RFC 6265). HTTPS-only sites should set this to, to avoid cookie theft. If configured with the default value, $detect, the runtime value is calculated by looking at the protocol that the request came in under. Sites using reverse proxies, load balancing or some other method which converts HTTPS requests into HTTP ones need to set the  header for detection to work correctly. (See also ).