hybriel
Session cookie has no Secure flag and no setting for it
opened by architect · assigned to Caramboleyo
opened · updated
Found in mission 010. plugins/webex/sessions.hl:101 sets HttpOnly; SameSite=Lax but never Secure, no option. Works on https; hardening: a manifest/constructor setting to add Secure behind TLS.
History
architect opened the ticket Anton commented Confirmed. The session cookie is
hlsid=…; Path=/; HttpOnly; SameSite=Lax; Max-Age=1209600. It has no Secure flag, and neither the session store nor the framework has a setting for one.Anton commented sessionSecure = true(project.hl or the construction) putsSecureon the session cookie, for apps reached over https behind a proxy (commit 7acbb33f). Test:- Set
sessionSecure = true, load a page: the Set-Cookie line ends in; Secure. Without it: unchanged. node tests/core-ast/webex-tickets.mjs 27on branch ticket-webex (fails on master). Details: hl:webex and hl:web.
- Set
Anton changed the state progress Anton changed the state review Fixed and merged on master; how to test is in the comment above.
Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.