Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check that all Matomo cookies are set with the Secure flag in the UI #12841

Closed
mattab opened this issue May 7, 2018 · 1 comment
Closed

Check that all Matomo cookies are set with the Secure flag in the UI #12841

mattab opened this issue May 7, 2018 · 1 comment
Labels
c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github.
Milestone

Comments

@mattab
Copy link
Member

mattab commented May 7, 2018

We got a security report piwik_lang Cookie has problem(s) piwik_lang = language%3Dczo1OiJ6aC10dyI7%3A_%xxxxx; Host = OURSITE; Path = / 1. Cookie does not have secure attribute.

-> Let's check and ensure that all our cookies have the Secure flag, when Matomo is used over HTTPS.

@mattab mattab added the c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. label May 7, 2018
@mattab mattab added this to the 3.6.0 milestone May 7, 2018
@diosmosis
Copy link
Member

@mattab checked and the lang & (now unused) auth cookie are both secure if HTTPS is used. The tracker cookies aren't, but I think we want them to be applied regardless of protocol. Closing this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github.
Projects
None yet
Development

No branches or pull requests

2 participants