Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider setting HttpOnly flag on session cookie #1665

Open
strugee opened this issue Jun 19, 2018 · 0 comments
Open

Consider setting HttpOnly flag on session cookie #1665

strugee opened this issue Jun 19, 2018 · 0 comments
Labels
Milestone

Comments

@strugee
Copy link
Member

strugee commented Jun 19, 2018

I believe we should be able to do this since the web UI acquires its own OAuth tokens and does stuff with that. Although I guess if it's compromised via an XSS attack the XSS code could maybe just steal the OAuth tokens? I think this depends on how we scope things out. I may end up filing a followup to audit that.

@strugee strugee added this to the Future milestone Jun 19, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant