For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

draco's avatar
draco
Icon for Nimbostratus rankNimbostratus
Mar 11, 2020

Http only flag set on applications cookies

Hi All

 

If i set the http only attribute for the cookies learnt in the ASM policy, then when I access the web application, and inspect the same via browser, it should show that the cookie has http only attribute enabled??

1 Reply

  • P_K's avatar
    P_K
    Icon for Altostratus rankAltostratus

    That is correct! You are basically forcing browser to access cookies via http and https by enabling httponly attribute in ASM.