Session cookie has no Secure flag and no setting for it
open
opened · updated
Found in mission 010. plugins/webex/sessions.hl:101 sets HttpOnly; SameSite=Lax but never Secure, no option. Works on https; hardening: a manifest/constructor setting to add Secure behind TLS.