Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nhsuk-cookie-consent cookie secure attribute #114

Open
nhsbsa-Will opened this issue Feb 9, 2021 · 0 comments
Open

nhsuk-cookie-consent cookie secure attribute #114

nhsbsa-Will opened this issue Feb 9, 2021 · 0 comments

Comments

@nhsbsa-Will
Copy link

Hi,

Should the nhsuk-cookie-consent cookie have the secure attribute? Guidance from GDS here says "You should only send cookies with the Secure attribute and, when appropriate, the HttpOnly attribute. These flags provide additional assurances about how browsers should handle cookies."

Currently the nhsuk-cookie-consent cookie doesn't have secure checked, as can be seen in the attached screenshot.

Cheers.
Screenshot 2021-02-09 at 11 09 30

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant