github / github/codeql

False positive: cs/web/broad-cookie-domain for Domain = null or ""

Open
#15,168 0 comments 0 reactions 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

cs/web/broad-cookie-domain is triggered when creating a System.Web.HttpCookie with `Domain=null`, but should not report. I believe it would also trigger when `Domain=""`, and I believe that would also be a false positive, but I have not tested that.

According to MDN:
> If the server does not specify a `Domain`, the cookies are available on the server _but not on its subdomains_. Therefore, specifying `Domain` is less restrictive than omitting it.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#domain_attribute

In System.Web.HttpCookie, setting `Domain=null` _ensures_ that the server will omit the cookie (which is _more restrictive_), otherwise it may default to some arbitrary value from the web.config.

**Code samples or links to source code**

Microsoft Reference Source for System.Web.HttpCookie where the `domain=` string is ommitted if `Domain=null` or `Domain=""`:
https://github.com/microsoft/referencesource/blob/51cf7850defa8a17d815b4700b67116e3fa283c2/System.Web/HttpCookie.cs#L460-L463

Contributor guide

Open the contributing guide

Research direction

Start with the cs/web/broad-cookie-domain query and compare its handling of System.Web.HttpCookie.Domain with the linked Microsoft Reference Source file. Confirm the behavior for Domain=null and Domain="", then ensure those cases are not reported while genuinely broad cookie domains remain covered.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.