False positive: cs/web/broad-cookie-domain for Domain = null or ""
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
cs/web/broad-cookie-domain is triggered when creating a System.Web.HttpCookie with `Domain=null`, but should not report. I believe it would also trigger when `Domain=""`, and I believe that would also be a false positive, but I have not tested that.
According to MDN:
> If the server does not specify a `Domain`, the cookies are available on the server _but not on its subdomains_. Therefore, specifying `Domain` is less restrictive than omitting it.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#domain_attribute
In System.Web.HttpCookie, setting `Domain=null` _ensures_ that the server will omit the cookie (which is _more restrictive_), otherwise it may default to some arbitrary value from the web.config.
**Code samples or links to source code**
Microsoft Reference Source for System.Web.HttpCookie where the `domain=` string is ommitted if `Domain=null` or `Domain=""`:
https://github.com/microsoft/referencesource/blob/51cf7850defa8a17d815b4700b67116e3fa283c2/System.Web/HttpCookie.cs#L460-L463
貢獻指南
評估
這個 Issue 還沒有評估資料。