Uploaded image for project: 'MyFaces Core'
  1. MyFaces Core
  2. MYFACES-3177

Add secure flag for cookies if the page is accessed over a secure protocol

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 2.0.7, 2.1.1
    • 2.0.8, 2.1.2
    • None
    • None

    Description

      We did some security tests for our application and one of the results was that for example the oam.Flash.RENDERMAP.TOKEN should be marked as secure if the page is accessed via https.

      http://download.oracle.com/javaee/6/api/javax/servlet/http/Cookie.html#setSecure(boolean)

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            jakobkorherr Jakob Korherr
            cadimmek Carsten Dimmek
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment