-
Bug
-
Resolution: Fixed
-
Minor
-
None
Jenkins' remember me cookie (ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE) is set without the HttpOnly flag.
Both the JSESSIONID and the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookies can be used interchangeably to access the application.
- is duplicated by
-
JENKINS-24840 Session cookie not set with HttpOnly flag
- Resolved