File tree Expand file tree Collapse file tree 1 file changed +2
-1
lines changed
src/java/detectors/insecure_cookie Expand file tree Collapse file tree 1 file changed +2
-1
lines changed Original file line number Diff line number Diff line change @@ -12,7 +12,7 @@ public class InsecureCookie {
12
12
// {fact rule=insecure-cookie@v1.0 defects=1}
13
13
public static void cookieInsecureByDefaultNoncompliant (HttpServletResponse response ) {
14
14
Cookie cookie = new Cookie ("name" , "value" );
15
- // Noncompliant: by default, the Cookie is not secure.
15
+ // Noncompliant: by default, the Cookie is not secure and not httpOnly .
16
16
response .addCookie (cookie );
17
17
}
18
18
// {/fact}
@@ -22,6 +22,7 @@ public static void cookieSecureCompliant(HttpServletResponse response) {
22
22
Cookie cookie = new Cookie ("name" , "value" );
23
23
// Compliant: the Cookie is secured.
24
24
cookie .setSecure (true );
25
+ cookie .setHttpOnly (true );
25
26
response .addCookie (cookie );
26
27
}
27
28
// {/fact}
You can’t perform that action at this time.
0 commit comments