<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007c70NRCAYOkta Classic EngineAuthenticationAnswered2025-03-20T09:00:23.000Z2022-04-27T15:26:47.000Z2022-05-24T15:47:30.000Z

SamiB.72222 (Customer) asked a question.

okta-oauth-* Cookies are not flagged as HttpOnly

Hello,

 

Our Security team is raising a warning about okta cookies not being flagged as HttpOnly, this is can prevent us to use Okta in future.

 

Is there any particular reason for not flagging these cookies as HttpOnly?

 

Thanks.

Sami


    • ghxfj (ghxfj)

      Hello @paul.stiniguta1.508386743840768E12 (Okta, Inc.)​ 

       

      Our company has exactly the same question, we would really appreciate it if you can clarify it.

       

      Same as Sami said, the question is particularly about okta-oauth-* cookies.

       

      Many thanks,

      Kon

      Expand Post
    • hryb0 (hryb0)

      Hi @paul.stiniguta1.508386743840768E12 (Okta, Inc.)​ 

      A recent PEN test of the application I work on has also raised questions about HttpOnly on okta-oauth-* cookies.

      Clarification on this would be greatly appreciated.

      Thanks,

      Jaimie

      • hryb0 (hryb0)

        I also asked about this on the devforum.

        I got the following answer from bdemers (from the Okta team):

         

        Setting cookies to HttpOnly would prevent JavaScript from reading the value. If you are building a SPA application, the JS must have access to these values (as that is where the auth flow starts)

        Expand Post
  • SamiB.72222 (Customer)

    Hello Paule,

     

    Thanks for your answer, we've already found that forum thread but it doesn't answer fully our question.

     

    In our case these cookies “okta-oauth-state” “okta-oauth-nonce” “okta-oauth-redirect-params" are not flagged as HttpOnly which are more sensitive than JSESSIONID cookie

     

    okta 

    Thanks

    Sami

    Expand Post
This question is closed.
Loading
okta-oauth-* Cookies are not flagged as HttpOnly