Sign in to Community
Sign in to view all badges
I am trying to figure out how can I make my existing cookies secure by adding secure attribute (PS. I am newbie to cookies).
@Shaheena_Sheikh ,if you don't make your cookie secure, then the cookie can be transmitted over the HTTP connection. so if you use HTTPS also, it is good practice to make your cookie secure.
Check below code
Cookie emailCookie = new Cookie("email", email);emailCookie.setPath("/");emailCookie.setMaxAge(31536000);emailCookie.setPath(";Path=/;HttpOnly;");;emailCookie.setSecure(true);response.addCookie(emailCookie);
Hi @Shaheena_Sheikh ,
Is your pages are rendered over https protocal?? If so OOTB will add secure flags on all cookies. You can additionally achieve this through api as well .
Check out the below thread for similar query
You can set HttpOnly and Secure flags to cookie. Check the below Cookie API documentation. Use setSecure(boolean flag) and setHttpOnly(boolean isHttpOnly).