Your achievements

Level 1

0% to

Level 2

Tip /
Sign in

Sign in to Community

to gain points, level up, and earn exciting badges like the new
Bedrock Mission!

Learn more

View all

Sign in to view all badges

SOLVED

setting Secure and HttpOnly flag in Cookie

Avatar

Level 2

Hi,

I have the below requirement could someone provide inputs as what could be done

  • I need to set the secure flag for login-token cookie. Currently "TokenUtil.createCredential()" method is having the argument to set the cookie as HttpOnly.
  • I need the sessionPersistence cookie to be HttpOnly and secure.

Please suggest a way to achieve this in CQ5 version 5.6.1

Thanks,

Satheeshraj V

1 Accepted Solution

Avatar

Correct answer by
Level 10
1 Reply

Avatar

Level 2

In the above provided link there was no clue to set secure flag for 'login-token' cookie and sessionPersistence cookie.

Avatar

Administrator

Hi

Please find below some reference article which could come as a help to you:-

Link:- http://help-forums.adobe.com/content/adobeforums/en/experience-manager-forum/adobe-experience-manage...

// If the request is over https out of the box should be setting the secure flag on all cookies.  In case you are terminating SSL on another layers like lb, dispatcher configure  Felix SSL Filter.   You can also set using api.

 https://docs.oracle.com/javase/7/docs/api/java/net/HttpCookie.html 

 

Link :- http://www.adobe.com/devnet/coldfusion/articles/coldfusion-securing-apps.html

Link :- https://blogs.oracle.com/jluehe/entry/ow_to_configure_the_security

I think this come as a help to you.

 

Thanks and Regards

Kautuk Sahni

Avatar

Correct answer by
Level 10