@qualle opened this Issue on June 24th 2020

The Cookie "_pk_testcookie.1.b4ee=1; _pk_id.1.b4ee=..." is set by matomo, which leads to a security warning "Security: Cookie Does Not Contain The "HTTPOnly" Attribute" on the security scanner qualysguard.

Can you add the HTTPOnly Attribute?

How to reproduce: Run a security test on any site with installed matomo (for eg. with qualysguard from qualys). Check results.

Expected behaviour: No warnings from the security scanner.

Greetings

@Findus23 commented on June 24th 2020 Member

Hi,

Those cookies are set by the matomo.js tracking script which means you can't set them HTTPOnly as this means that they would not be accessible via Javascript.

@nsiddams-opentext commented on December 7th 2022

Hi @Findus23 ,

From the above comment made by you on June 24,2020

Those cookies are set by the matomo.js tracking script which means you can't set them HTTPOnly as this means that they would not be accessible via Javascript.
I understand that we cant set the cookies as HTTPOnly so it still remains as security issue , so can we disable these cookies and will it have any impact on the Matomo tracking functionality?

@MatomoForumNotifications commented on December 7th 2022

This issue has been mentioned on Matomo forums. There might be relevant details there:

https://forum.matomo.org/t/pk-id-and-pk-ses-cookies-set-by-matomo-is-not-httponly/48615/2

This Issue was closed on June 24th 2020
Powered by GitHub Issue Mirror