how to set httponly and session cookie for java web application

安稳与你 提交于 2019-12-17 22:54:00

问题


I am working on an XSS (cross site scripting) issue. My application runs on an Oracle Weblogic portal. We use Servlet version 2.5.

I have added the below 3 lines of code in the filter for setting httponly and secure cookies, and it is working fine.

String sessionid = req.getSession().getId();
res.setHeader("Set-Cookie", "JSESSIONID=" +  sessionid + ";HttpOnly");
res.setHeader("SET-COOKIE", "JSESSIONID=" + sessionid + "; secure");

The issue is when I logout and login immediately in the same browser. I am able to login, but after that, on the jsp pages I am getting a session timeout issue. We use weblogic related apis. The request.getuserprinical() api is returning null.. guess it is setting to null.

Please share any ideas.

If there are any other ways to set httponly or secure flag, please help.


回答1:


Depending on the specifics of your web container, modifying container-managed session cookies within an app can cause the app server to toss the existing session and create a new one. I've observed this on Tomcat but it may be similar for Weblogic.

If you're using Servlets 3.0, you can actually instruct the app server to ensure that all session cookies are HttpOnly and Secure with the following fragments:

<session-config>
  <cookie-config>
    <secure>true</secure>
    <http-only>true</http-only>
  </cookie-config>
</session-config>

This is a better approach than manually hacking on the cookies with a filter.

FYI: I've also written a Java library that injects a number of security related response headers in Servlet based apps.




回答2:


You need to use following syntax to set both httponly and Secure flags

JSESSIONID=ABC3423DF...SDF;HttpOnly;Secure



回答3:


I have used <http-only> and <secure> tags in web.xml to set the secure attributes and it worked.

<session-config>
 <cookie-config>
  <http-only>true</http-only>
 </cookie-config>
<session-config>


来源:https://stackoverflow.com/questions/15510354/how-to-set-httponly-and-session-cookie-for-java-web-application

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!