Forum Discussion
mahmad2_222556
Nimbostratus
Sep 14, 2018Disable http for Cookie persistance setup
We have a requirement from an IVR vendor to enable Cookie without HTTP. I tried to configure Cookie w/o http and got an error that Cookie persistence requires an HTTP or FastHTTP profile to be associ...
Aaron_Booker
Employee
Sep 15, 2018If you are going to use cookie persistence, for this application running through BIG-IP, it sounds like you need to disable the HTTPOnly Attribute in the cookie persistence profile. Without the HttpOnly flag a client side script can access the cookie. I should note that the HttpOnly flag protects against XSS attacks. Here is more information:
K83419154: Overview of cookie persistence
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
