For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/code_security/static_analysis/static_analysis_rules/csharp-security/cookie-http-only.md. A documentation index is available at /llms.txt.
This product is not supported for your selected Datadog site. ().

Metadata

ID: csharp-security/cookie-http-only

Language: C#

Severity: Warning

Category: Security

CWE: 614

Description

Cookies must only be used for HTTP connections. Otherwise, client-side scripts can access cookies and compromise the user security.

Learn More

Non-Compliant Code Examples

class MyClass {
    public static void setSecureCookie()
    {
        HttpCookie myCookie = new HttpCookie("my cookie");
        Console.WriteLine("Hello World");
        myCookie.HttpOnly = false;
    }
}
class MyClass {
    public static void setInsecureCookie()
    {
        HttpCookie myCookie = new HttpCookie("my cookie");
        Console.WriteLine("Hello World");
        myCookie.HttpOnly = false;
    }
}

Compliant Code Examples

class MyClass {
    public static void setSecureCookie()
    {
        // Safe: HttpOnly is set to true
        HttpCookie myCookie = new HttpCookie("my cookie");
        myCookie.HttpOnly = true;
    }
}
https://static.datadoghq.com/static/images/logos/github_avatar.svg https://static.datadoghq.com/static/images/logos/vscode_avatar.svg jetbrains

Seamless integrations. Try Datadog Code Security