Skip to content

Commit 29389b2

Browse files
authored
Add httponly to compliant insecure-cookie example (#71)
Since we now detect more issues under the same DetectorID, our example must be strengthened.
1 parent aaeef85 commit 29389b2

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

src/java/detectors/insecure_cookie/InsecureCookie.java

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ public class InsecureCookie {
1212
// {fact rule=insecure-cookie@v1.0 defects=1}
1313
public static void cookieInsecureByDefaultNoncompliant(HttpServletResponse response) {
1414
Cookie cookie = new Cookie("name", "value");
15-
// Noncompliant: by default, the Cookie is not secure.
15+
// Noncompliant: by default, the Cookie is not secure and not httpOnly.
1616
response.addCookie(cookie);
1717
}
1818
// {/fact}
@@ -22,6 +22,7 @@ public static void cookieSecureCompliant(HttpServletResponse response) {
2222
Cookie cookie = new Cookie("name", "value");
2323
// Compliant: the Cookie is secured.
2424
cookie.setSecure(true);
25+
cookie.setHttpOnly(true);
2526
response.addCookie(cookie);
2627
}
2728
// {/fact}

0 commit comments

Comments
 (0)