Uploaded image for project: 'MyFaces Core'
  1. MyFaces Core
  2. MYFACES-4418

Same Site and HSTS support

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Critical
    • Resolution: Duplicate
    • 2.3.9
    • None
    • General
    • None
    • Redhat Linux

    Description

      Security auditors have pointed out that the session cookie oam.Flash.RENDERMAP.TOKEN and other  myfaces cookies are not handling Same Site and HTTP Strict Transport Security. 

      I do not know how to reply to this although I have looked around for information I cannot find any. 

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            indri.cilia@gmail.com Andrew Charles Cilia
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: