I added httpOnly flag in the XML, that worked for me.    Does this solution 
sound right?

    <bean id="ticketGrantingTicketCookieGenerator" 
class="org.jasig.cas.web.support.CookieRetrievingCookieGenerator"
          c:casCookieValueManager-ref="cookieValueManager"
          p:cookieHttpOnly="true"  



On Thursday, March 9, 2017 at 10:21:48 AM UTC-5, Yan Zhou wrote:
>
> Hi there, 
>
> I have a CAS 4.1.X overlay, servlet API version 3 in POM.xml, and CAS 
> running on tomcat7. 
>
> I observed that TGC cookie is set to Secure, but NOT httpOnly.  Tomcat7 
> default to HttpOnly for session cookie but it does not know about CAS TGC 
> cookie, so the CAS web app's session cookie has HttpOnly set, but TGC 
> cookie does not.
>
> The source code in CookieRetrievingCookieGenerator.java shows, CAS would 
> set to HttpOnly if  "RememberMe" is on.
>
> Am I missing something, should not TGC cookie always have HttpOnly on all 
> the times? This URL explains how to customize CAS to do that. But I am 
> wondering why this would require customization. 
>
> http://daodecode.com/2013/03/25/castgc-cookie-and-httponly-flag/
>
> Thx!
> Yan
>
>     public void addCookie(final HttpServletRequest request, final 
> HttpServletResponse response, final String cookieValue) {
>         final String theCookieValue = 
> this.casCookieValueManager.buildCookieValue(cookieValue, request);
>
>         if 
> (!StringUtils.hasText(request.getParameter(RememberMeCredential.REQUEST_PARAMETER_REMEMBER_ME)))
>  
> {
>             super.addCookie(response, theCookieValue);
>         } else {
>             final Cookie cookie = createCookie(theCookieValue);
>             cookie.setMaxAge(this.rememberMeMaxAge);
>             if (isCookieSecure()) {
>                 cookie.setSecure(true);
>             }
>             if (isCookieHttpOnly()) {
>                 final Method setHttpOnlyMethod = 
> ReflectionUtils.findMethod(Cookie.class, "setHttpOnly", boolean.class);
>                 if(setHttpOnlyMethod != null) {
>                     cookie.setHttpOnly(true);
>                 } else {
>                     logger.debug("Cookie cannot be marked as HttpOnly; 
> container is not using servlet 3.0.");
>                 }
>             }
>             response.addCookie(cookie);
>         }
>     }
>
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/4ffe7293-67ca-4bf6-be35-345614a1d005%40apereo.org.

Reply via email to