Welcome! Log In Create A New Profile

Advanced

RE: secure and httponly cookies

March 08, 2016 02:46AM
Thing is its failing in the vulnerability scan (nexpose tool is used) saying cookie is not secure or httponly.

From: nginx [mailto:nginx-bounces@nginx.org] On Behalf Of Aapo Talvensaari
Sent: Monday, March 07, 2016 11:34 PM
To: nginx@nginx.org
Subject: Re: secure and httponly cookies

On Tuesday, 8 March 2016, Krishna Kumar K K <krishna@brocade.com<mailto:krishna@brocade.com>> wrote:
I am able to modify the set-cookie header from the server to flag it secure. I am trying to do the same in the request header as well.

Those flags are instructions to client. They don't have meaning on request headers. Only on response headers.
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

secure and httponly cookies

krishna@brocade.com March 07, 2016 02:38PM

Re: secure and httponly cookies

Lucas Rolff March 07, 2016 02:48PM

Re: secure and httponly cookies

krishna@brocade.com March 07, 2016 02:54PM

Re: secure and httponly cookies

Lucas Rolff March 07, 2016 03:02PM

Re: secure and httponly cookies

krishna@brocade.com March 07, 2016 03:15PM

Re: secure and httponly cookies

Aapo Talvensaari March 07, 2016 03:32PM

Re: secure and httponly cookies

Robert Paprocki March 07, 2016 03:38PM

Re: secure and httponly cookies

Aleksandar Lazic March 07, 2016 04:26PM

RE: secure and httponly cookies

krishna@brocade.com March 07, 2016 04:52PM

Re: secure and httponly cookies

Francis Daly March 07, 2016 05:58PM

RE: secure and httponly cookies

krishna@brocade.com March 07, 2016 07:40PM

Re: secure and httponly cookies

Aapo Talvensaari March 08, 2016 02:36AM

RE: secure and httponly cookies

krishna@brocade.com March 08, 2016 02:46AM

RE: secure and httponly cookies

Aleksandar Lazic March 08, 2016 03:00AM

RE: secure and httponly cookies

krishna@brocade.com March 07, 2016 04:54PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 177
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready