Skip to content

Could the sessionId cookie be made httpOnly to avoid potential XSS? #7045

@Loki-Afro

Description

@Loki-Afro

Is your feature request related to a problem? Please describe.
Currently the sessionId can not be made httpOnly

Describe the solution you'd like
sessionId to be made httpOnly

Describe alternatives you've considered
going the oauth route might not be worth it and might be affected too?

documentation I found https://docs.etherpad.org/cookies.html

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions