HTTP Only flag on Shibboleth IdP cookies

WULMS Alex Alex.WULMS at swift.com
Mon Apr 7 08:39:31 EDT 2014


Hi,

 

Referring to a discussion from two years ago about IdP cookie protection
(see
http://shibboleth.1660669.n2.nabble.com/IdP-cookie-protection-td7311929.html
):

 

Would it be possible to make a new configuration parameter in the IdP that
when set to true, the IdP will set the HTTP Only flag on the cookies that it
generates but when the flag is not set at all (for old deployments) or set
to false, the IdP will not set the HTTP Only flag.

 

It would offer a slightly better protection against XSS and the deployer can
experiment for himself if it works with the container that the deployer
uses.

 

Thanks and kind regards,

Alex Wulms

 

 

Alex Wulms
SWIFT | Lead Developer / E-channel 
Tel: +32 2 6553931
 <http://www.swift.com/> www.swift.com

This e-mail and any attachments thereto may contain information which is
confidential and/or proprietary and intended for the sole use of the
recipient(s) named above. If you have received this e-mail in error, please
immediately notify the sender and delete the mail.  Thank you for your
co-operation.  SWIFT reserves the right to retain e-mail messages on its
systems and, under circumstances permitted by applicable law, to monitor and
intercept e-mail messages to and from its systems.

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140407/4eb40a8c/attachment.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4518 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20140407/4eb40a8c/attachment.bin 


More information about the dev mailing list