Support Article
How to set cookies to HTTP-Only?
SA-4314
Summary
How to set JESSIONID, LB, and Pega-Rules cookies to HTTPOnly and secure?
Resolution
- Apply HFix-9206.
- Add <env name="cookie/HttpOnly" value="true" /> to prconfig.xml file.
- Add the following line to prconfig.xml file (no hotfix needed) to set secure on cookies: <env value="true" name="HTTP/SetSecureCookie"/>
Published November 30, 2016 - Updated October 8, 2020
Have a question? Get answers now.
Visit the Collaboration Center to ask questions, engage in discussions, share ideas, and help others.