Project

General

Profile

Actions

Bug #78835

closed

Cookie be_lastLoginProvider doesn't respect httpOnly and Secure flags

Added by Bas v.d. Wiel over 7 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2016-11-29
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
8
PHP Version:
7.0
Tags:
Complexity:
Is Regression:
No
Sprint Focus:
On Location Sprint

Description

My vulnerability scanner keeps firing on be_lastLoginProvider cookie not being secure and httpOnly.

Actions

Also available in: Atom PDF