ClusterLabs / ClusterLabs/hawk-apiserver

Missing 'HttpOnly' Cookie Attribute (HTTP) for hawk-apiserver

Open
#55 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
12
Forks
12
Avg merge
33m
Merged PRs (30d)
2

Description

hawk-apiserver running on port 7630 is showing security warning Missing 'HttpOnly' Cookie Attribute (HTTP). Is there a way to enable httponly cookie on this configuration.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start at the hawk-apiserver HTTP entry point on port 7630 and trace where its cookies are created or configured. Reproduce the security warning, determine the applicable configuration or response path, and consider the issue done when the cookie includes the HttpOnly attribute without breaking existing behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.