Skip to content

Could the sessionId cookie be made httpOnly to avoid potential XSS? #7045

@Loki-Afro

Description

@Loki-Afro

Is your feature request related to a problem? Please describe.
Currently the sessionId can not be made httpOnly

Describe the solution you'd like
sessionId to be made httpOnly

Describe alternatives you've considered
going the oauth route might not be worth it and might be affected too?

documentation I found https://docs.etherpad.org/cookies.html

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions