Forum Discussion
How to properly insert HttpOnly and Secure cookie directives?
The F5 (running LTM 11.2) does not separate HTTP headers correctly, which means it also can't successfully separate HTTP Set-Cookie headers.
Given a header:
Set-Cookie: sso.auth_token=deleted; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
The LB appears to do something funny with the semicolons and/or equals signs. It thinks "Expires" and "01-Jan-1970" are also cookie names using the [HTTP::cookie names] iRule command.
Using the [HTTP::header "Set-Cookie"] command doesn't do any better. The LB also thinks strings that are not cookie headers (e.g. "Expires") actually are.
I haven't looked for an existing bug for this, but may do so in the future. If I don't find one, I'll open one.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
