# Secure cookie implementation

**URL:** <https://help.nextcloud.com/t/secure-cookie-implementation/21854>\
**Category:** ℹ️ Support\
**Tags:** security, nc12\
**Created:** [October 3, 2017, 8:15pm UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854 "2017-10-03T20:15:01Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mzeyrek](https://help.nextcloud.com/user_avatar/help.nextcloud.com/mzeyrek/32/5837_2.png) [@mzeyrek](https://help.nextcloud.com/u/mzeyrek)\
**Post date:** [October 3, 2017, 8:15pm UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/1 "2017-10-03T20:15:02Z")

</div>

Did a quick penetration test over [https://pentest-tools.com/website-vulnerability-scanning/web-server-scanner?run](https://pentest-tools.com/website-vulnerability-scanning/web-server-scanner?run) for my locally hosted nextcloud server and recieved as medium-secure server result due secure cookies were not enabled )risk description bottom). Are there any plans to implement secure cookies or we need to that at web server level ?

There is a nice article at [https://www.tunetheweb.com/security/http-security-headers/secure-cookies/](https://www.tunetheweb.com/security/http-security-headers/secure-cookies/) how to implement web-server while i was wondering if there are any future implementations on roadmap that might conflict with webserver config.

Risk description:  
Since the Secure flag is not set on the cookie, the browser will send it over an unencrypted channel (plain HTTP) if such a request is made. Thus, the risk exists that an attacker will intercept the clear-text communication between the browser and the server and he will steal the cookie of the user. If this is a session cookie, the attacker could gain unauthorized access to the victim’s web session.

Recommendation:  
We recommend reconfiguring the web server in order to set the flag(s) Secure to all sensitive cookies.

More information about this issue:  
[https://blog.dareboost.com/en/2016/12/secure-cookies-secure-httponly-flags/](https://blog.dareboost.com/en/2016/12/secure-cookies-secure-httponly-flags/).

---

<div class="post-metadata">

**Author:** ![alfred](https://help.nextcloud.com/letter_avatar/alfred/32/5_5575768a8748004e209b776fc1b2916d.png) [@alfred](https://help.nextcloud.com/u/alfred)\
**Post date:** [October 4, 2017, 9:35am UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/2 "2017-10-04T09:35:51Z")

</div>

Openvas also complains about that and gives a “medium” warning:

> Summary
> 
> The host is running a server with SSL/TLS and is prone to information disclosure vulnerability.  
> Vulnerability Detection Result
> 
> The cookies:
> 
> Set-Cookie: 45342agfd4=_ **replaced** _; path=/; HttpOnly
> 
> are missing the “secure” attribute.
> 
> Solution
> 
> Solution type: Mitigation Mitigation
> 
> Set the ‘secure’ attribute for any cookies that are sent over a SSL/TLS connection.  
> Affected Software/OS
> 
> Server with SSL/TLS.  
> Vulnerability Insight
> 
> The flaw is due to cookie is not using ‘secure’ attribute, which allows cookie to be passed to the server by the client over non-secure channels (http) and allows attacker to conduct session hijacking attacks.
> 
> Impact Level: Application  
> Vulnerability Detection Method
> 
> Details: SSL/TLS: Missing `secure` Cookie Attribute (OID: 1.3.6.1.4.1.25623.1.0.902661)
> 
> Version used: $Revision: 5543 $
> 
> References
> 
> Other:   
> [https://www.owasp.org/index.php/SecureFlag](https://www.owasp.org/index.php/SecureFlag)  
> [http://www.ietf.org/rfc/rfc2965.txt](http://www.ietf.org/rfc/rfc2965.txt)  
> [Testing for cookies attributes (OTG-SESS-002) - OWASP](https://www.owasp.org/index.php/Testing_for_cookies_attributes_(OWASP-SM-002))

---

<div class="post-metadata">

**Author:** ![mzeyrek](https://help.nextcloud.com/user_avatar/help.nextcloud.com/mzeyrek/32/5837_2.png) [@mzeyrek](https://help.nextcloud.com/u/mzeyrek)\
**Post date:** [October 4, 2017, 7:07pm UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/3 "2017-10-04T19:07:15Z")

</div>

SameSiteCookieMiddleware.php that implements this feature but somehow not working for me.

```
	protected function setSameSiteCookie() {
		$cookieParams = $this->request->getCookieParams();
		$secureCookie = ($cookieParams['secure'] === true) ? 'secure; ' : '';
		$policies = [
			'lax',
			'strict',
		];
		// Append __Host to the cookie if it meets the requirements
		$cookiePrefix = '';
		if($cookieParams['secure'] === true && $cookieParams['path'] === '/') {
			$cookiePrefix = '__Host-';
		}
```

---

<div class="post-metadata">

**Author:** ![MichaIng](https://help.nextcloud.com/user_avatar/help.nextcloud.com/michaing/32/2125_2.png) [@MichaIng](https://help.nextcloud.com/u/MichaIng)\
**Post date:** [October 4, 2017, 8:43pm UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/4 "2017-10-04T20:43:46Z")

</div>

I thought this was implemented as well as \_host flag if nc is not in sub dir.

Did this issue found it’s way to github to get quick dev attention?

---

<div class="post-metadata">

**Author:** ![mzeyrek](https://help.nextcloud.com/user_avatar/help.nextcloud.com/mzeyrek/32/5837_2.png) [@mzeyrek](https://help.nextcloud.com/u/mzeyrek)\
**Post date:** [October 4, 2017, 8:57pm UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/5 "2017-10-04T20:57:42Z")

</div>

i have a dedicated domain and not running in any subdomain or subidr.  
Thanks for github suggestion, i’ve just raised as an issue there

---

<div class="post-metadata">

**Author:** ![tflidd](https://help.nextcloud.com/letter_avatar/tflidd/32/5_5575768a8748004e209b776fc1b2916d.png) [@tflidd](https://help.nextcloud.com/u/tflidd)\
**Post date:** [October 5, 2017, 6:51am UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/6 "2017-10-05T06:51:19Z")

</div>

ref: [https://github.com/nextcloud/server/issues/6767](https://github.com/nextcloud/server/issues/6767)

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 2, 2024, 2:38pm UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/7 "2024-12-02T14:38:40Z")

</div>



---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 4, 2024, 1:57pm UTC](https://help.nextcloud.com/t/secure-cookie-implementation/21854/8 "2024-12-04T13:57:32Z")

</div>


