Ensure cookies have the secure flag

Metadata

ID: csharp-security/cookie-secure-flag

Language: C#

Severity: Warning

Category: Security

Description

Cookies must always have the secure attribute so that they are not sent through an unencrypted HTTP session.

Learn More

Non-Compliant Code Examples

class MyClass {
    public static void setSecureCookie()
    {
        HttpCookie myCookie = new HttpCookie("my cookie");
        Console.WriteLine("Hello World");
        myCookie.Secure = false;
    }
}
class MyClass {
    public static void setInsecureCookie()
    {
        HttpCookie myCookie = new HttpCookie("my cookie");
        Console.WriteLine("Hello World");
        myCookie.Secure = false;
    }
}