Your achievements

Level 1

0% to

Level 2

Tip /
Sign in

Sign in to Community

to gain points, level up, and earn exciting badges like the new
BedrockMission!

Learn more

View all

Sign in to view all badges

SOLVED

setting Secure and HttpOnly flag in Cookie

satheeshraj
Level 2
Level 2

Hi,

I have the below requirement could someone provide inputs as what could be done

  • I need to set the secure flag for login-token cookie. Currently "TokenUtil.createCredential()" method is having the argument to set the cookie as HttpOnly.
  • I need the sessionPersistence cookie to be HttpOnly and secure.

Please suggest a way to achieve this in CQ5 version 5.6.1

Thanks,

Satheeshraj V

1 Accepted Solution
Sham_HC
Correct answer by
Level 10
Level 10
6 Replies
satheeshraj
Level 2
Level 2

In the above provided link there was no clue to set secure flag for 'login-token' cookie and sessionPersistence cookie.

kautuk_sahni
Community Manager
Community Manager

Hi

Please find below some reference article which could come as a help to you:-

Link:- http://help-forums.adobe.com/content/adobeforums/en/experience-manager-forum/adobe-experience-manage...

// If the request is over https out of the box should be setting the secure flag on all cookies.  In case you are terminating SSL on another layers like lb, dispatcher configure  Felix SSL Filter.   You can also set using api.

 https://docs.oracle.com/javase/7/docs/api/java/net/HttpCookie.html 

 

Link :- http://www.adobe.com/devnet/coldfusion/articles/coldfusion-securing-apps.html

Link :- https://blogs.oracle.com/jluehe/entry/ow_to_configure_the_security

I think this come as a help to you.

 

Thanks and Regards

Kautuk Sahni

Sham_HC
Correct answer by
Level 10
Level 10
jamiec4451712
Level 3
Level 3

I know this is an old question, but our team ran into a very similar issue and I posted details of our solution here: https://experienceleaguecommunities.adobe.com/t5/adobe-experience-manager/aem-session-cookie-with-ht...