curationexperts / cypripedium

A Hyrax 3 application for the Federal Reserve Bank of Minneapolis
2 stars 3 forks source link

Set 'secure' attribute in cookies #593

Closed mark-dce closed 4 weeks ago

mark-dce commented 4 weeks ago

ISSUE Security scanning software may flag the lack of the secure attribure in cookies; even when other architetural components ensure that cookies are only sent by the application when communicating over TLS encrypted HTTPS.

RESOLUTION Ensure the attribute is set, even when sending over HTTPS