HttpOnly

Moderator: crythias

Locked
srivatsatatti
Znuny newbie
Posts: 85
Joined: 25 Jan 2011, 06:54
Znuny Version: OTRS 3
Company: eStomi Technologies Pvt Ltd
Contact:

HttpOnly

Post by srivatsatatti »

where can we set the cookie attribute to httponly?
OTRS 3.2.x, Linux Ubuntu, Mysql 5.1.
jojo
Znuny guru
Posts: 15020
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: HttpOnly

Post by jojo »

sorry, can you please specify your question?
"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
srivatsatatti
Znuny newbie
Posts: 85
Joined: 25 Jan 2011, 06:54
Znuny Version: OTRS 3
Company: eStomi Technologies Pvt Ltd
Contact:

Re: HttpOnly

Post by srivatsatatti »

Need to Enable HTTPOnly feature for session cookies.
OTRS 3.2.x, Linux Ubuntu, Mysql 5.1.
jojo
Znuny guru
Posts: 15020
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: HttpOnly

Post by jojo »

you already wrote this... but thats not explaining your question
"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
srivatsatatti
Znuny newbie
Posts: 85
Joined: 25 Jan 2011, 06:54
Znuny Version: OTRS 3
Company: eStomi Technologies Pvt Ltd
Contact:

Re: HttpOnly

Post by srivatsatatti »

In order to avoid accessing cookies through client side scripting, I want to enable cookie attribute to Httponly
OTRS 3.2.x, Linux Ubuntu, Mysql 5.1.
jojo
Znuny guru
Posts: 15020
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: HttpOnly

Post by jojo »

This would require some development but is not needed as OTRS uses a ChallengeToken
"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
Locked