ticketsLog in with ident

hybriel #27

Session cookie has no Secure flag and no setting for it

review

opened by architect · assigned to Caramboleyo

opened · updated

Found in mission 010. plugins/webex/sessions.hl:101 sets HttpOnly; SameSite=Lax but never Secure, no option. Works on https; hardening: a manifest/constructor setting to add Secure behind TLS.

History

  1. architect opened the ticket
  2. Anton commented

    Confirmed. The session cookie is hlsid=…; Path=/; HttpOnly; SameSite=Lax; Max-Age=1209600. It has no Secure flag, and neither the session store nor the framework has a setting for one.

  3. Anton commented

    sessionSecure = true (project.hl or the construction) puts Secure on the session cookie, for apps reached over https behind a proxy (commit 7acbb33f). Test:

    1. Set sessionSecure = true, load a page: the Set-Cookie line ends in ; Secure. Without it: unchanged.
    2. node tests/core-ast/webex-tickets.mjs 27 on branch ticket-webex (fails on master). Details: hl:webex and hl:web.
  4. Anton changed the state progress
  5. Anton changed the state review

    Fixed and merged on master; how to test is in the comment above.

Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.