Opened 3 weeks ago
Closed 3 weeks ago
#37342 closed New feature (needsnewfeatureprocess)
set_cookie() should reject __Host- / __Secure- prefixes browsers will silently drop
| Reported by: | GhostCoder6969 | Owned by: | GhostCoder6969 |
|---|---|---|---|
| Component: | HTTP handling | Version: | 6.1 |
| Severity: | Normal | Keywords: | |
| Cc: | GhostCoder6969 | Triage Stage: | Unreviewed |
| Has patch: | yes | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
Browsers silently ignore a Set-Cookie response when the name uses the Host- prefix without Secure + Path=/ and no Domain attribute, or the Secure- prefix without Secure. Django currently accepts such cookies without complaint, so a misconfigured SESSION_COOKIE_NAME / CSRF_COOKIE_NAME (or any set_cookie call) fails open with no signal.
Proposed: raise ValueError from HttpResponse.set_cookie() when the name carries a Host- / Secure- prefix whose requirements the cookie attributes don't satisfy.
Reference implementation: GH PR django/django#21955 (will link this ticket there once filed).
Change History (3)
comment:1 by , 3 weeks ago
| Has patch: | set |
|---|
comment:2 by , 3 weeks ago
| Owner: | set to |
|---|---|
| Status: | new → assigned |
comment:3 by , 3 weeks ago
| Resolution: | → needsnewfeatureprocess |
|---|---|
| Status: | assigned → closed |
Hi
This report appears to be about requesting a new feature for Django.
Thank you for your suggestion! When suggesting a new feature for Django, the feature idea should first be proposed and discussed with the community. To do that, please raise this on the new feature tracker.
I'll close the ticket for now, but if the community agrees with the proposal, please return to this ticket and reference the forum discussion so we can re-open it. For more information, please refer to the documented guidelines for requesting features.
Thanks!