Forum Discussion
matt_12671
Nimbostratus
Aug 26, 2013How to properly insert HttpOnly and Secure cookie directives?
My load balancer has an iRule that adds the HttpOnly and Secure cookie directives. The rules is adding the directives multiple times, and in the incorrect places. How can I get the directives added c...
matt_12671
Nimbostratus
Sep 04, 2013A co-worker and I figured out something that works for us:
set unsafe_cookie_headers [HTTP::header values "Set-Cookie"]
HTTP::header remove "Set-Cookie"
foreach set_cookie_header $unsafe_cookie_headers {
HTTP::header insert "Set-Cookie" "${set_cookie_header}; Secure; HttpOnly"
}
- matt_12671Sep 04, 2013
Nimbostratus
Evidently, I can't pick my own answer as the answer. If I could, I would pick this. - BinaryCanary_19Sep 18, 2013Historic F5 AccountBe careful about setting the secure attribute if the connection is not HTTPS: http://en.wikipedia.org/wiki/HTTP_cookieCookie_attributes
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
