Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-13272

Backport from 2.1.0 - Set HttpOnly and Secure flags for Ambari session cookies

    XMLWordPrintableJSON

Details

    • Task
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.0.2
    • 2.0.3
    • None
    • None

    Description

      Ambari should set the following flags for session cookies.

      1) https://www.owasp.org/index.php/HttpOnly

      2) https://www.owasp.org/index.php/SecureFlag

      #2 only needs to be set when people configure for Ambari HTTPS

      Attachments

        Issue Links

          Activity

            People

              rlevas Robert Levas
              rlevas Robert Levas
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: