How to set session cookie http-only in weblogic version 8

1.9k Views Asked by At

Is cookieHttpOnly available in Weblogic 8.x ?? I need to set the session cookies to HTTP only for security reasons and unable to find anything in the weblogic.xml deployment descriptor.

http://docs.oracle.com/cd/E13222_01/wls/docs81/webapp/weblogic_xml.html

Please help!

1

There are 1 best solutions below

0
user3483727 On

httpOnly cookie attribute is available from weblogic 9.2 onwards.

But there is a work around to this, check: https://www.owasp.org/index.php/HTTPOnly

For 9.2 see Weblogic descriptor elements for 9.2