redbot
redbot copied to clipboard
Cookie flags
- [ ] Secure
- [ ] HTTPOnly
- [ ] SameSite
others?
Could this include checking for compliance with the prerequisites for cookies with __Secure-
and __Host-
prefixes perhaps?
https://slides.com/maximtsoy/the-zen-of-cookies might help; in particular slide 30 (cc @muodov)
You could also check for "cookie folding": multiple cookies in a single Set-Cookie header used to be supported, but not anymore.
Not sure this is the right ticket to report it but related re SameSite. Redbot thinks it's invalid?
- General:
- The loid Set-Cookie header has an unknown attribute, 'SameSite'.
- The session_tracker Set-Cookie header has an unknown attribute, 'SameSite'.
- The csv Set-Cookie header has an unknown attribute, 'SameSite'.
Is that a known bug? Only thing I can think of is Reddit sends Secure before SameSite not after. Though the spec doesn't say it's invalid.
Scratch that.. one cookie does the reverse and still considered invalid
Set-Cookie: loid=randomstring; Domain=reddit.com; Max-Age=63071999; Path=/; expires=Wed, 04-Jan-2023 02:31:13 GMT; **secure; SameSite=None; Secure**
Set-Cookie: session_tracker=randomstring; Domain=reddit.com; Max-Age=7199; Path=/; expires=Mon, 04-Jan-2021 04:31:13 GMT; secure; **SameSite=None; Secure**
Set-Cookie: csv=1; Max-Age=63072000; Domain=.reddit.com; Path=/; Secure; SameSite=None
Set-Cookie: edgebucket=random; Domain=reddit.com; Max-Age=63071999; Path=/; secure
Server: snooserv