Andrew Charles Cilia created MYFACES-4418:
---------------------------------------------

             Summary: Same Site and HSTS support
                 Key: MYFACES-4418
                 URL: https://issues.apache.org/jira/browse/MYFACES-4418
             Project: MyFaces Core
          Issue Type: Improvement
          Components: General
    Affects Versions: 2.3.9
         Environment: Redhat Linux
            Reporter: Andrew Charles Cilia


Security auditors have pointed out that the session cookie 
oam.Flash.RENDERMAP.TOKEN and other  myfaces cookies are not handling Same Site 
and HTTP Strict Transport Security. 

I do not know how to reply to this although I have looked around for 
information I cannot find any. 

 



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to