Adding secure and httponly attributes to JSESSIONID cookie

Avatar

Avatar

Amuthesan

Avatar

Amuthesan

Amuthesan

09-02-2017

Hi All,

We have used session from request to store few data. When we access the session, it generates JSESSIONID cookie. But the generated JSESSIONID cookie does not have cookie attributes "secure" and "httponly".

Can anyone please provide me pointers on how to add these flags to the JSESSIONID cookie in AEM.

Thanks in advance,

Amuthesan

Replies

Avatar

Avatar

smacdonald2008

Total Posts

12.7K

Likes

1.4K

Correct Reply

2.3K

Avatar

smacdonald2008

Total Posts

12.7K

Likes

1.4K

Correct Reply

2.3K
smacdonald2008

10-02-2017

Avatar

Avatar

Amuthesan

Avatar

Amuthesan

Amuthesan

12-02-2017

Hi Scott,

Thanks for the reply. 

We are currently offloading the SSL at the dispatcher level and the communication with AEM is non SSL. And also if we enable the SSL for the AEM, all the cookies would be made secure and httponly, we do not want that. We want only the JSESSIONID cookie to be made secure. As we understand the cookie is created and managed by container, Is there any configuration/input that can be made to the container to create the cookie with the secure and httponly.

Thanks,

Amuthesan

Avatar

Avatar

Shaheena_Sheikh

Avatar

Shaheena_Sheikh

Shaheena_Sheikh

23-02-2021

Did you find a solution to this?