[E05-S02-T03] Secure/HttpOnly/SameSite attributes in production #238

Open
opened 2026-08-27 00:17:18 +00:00 by kpcto · 0 comments
Owner

Parent story: [E05-S02] Opaque DB-backed session (#73)

Intent

Set Secure, HttpOnly and SameSite cookie attributes in production.

Acceptance criteria

  • Session cookie sets Secure and HttpOnly attributes in production
  • Session cookie sets SameSite in production to prevent cross-site send

Explicitly out of scope

  • Token generation (E05-S02-T01)
  • Lookup hash storage (E05-S02-T02)
  • Logout revocation and expiration (E05-S02-T04/T05)
  • Admin API 401 to anonymous caller (E05-S02-T06)

Test plan

  • Automated test checks the Set-Cookie header under production config

Rollback note

  • Revert cookie attribute change and redeploy previous build

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E05-S02] Opaque DB-backed session (#73) ## Intent Set Secure, HttpOnly and SameSite cookie attributes in production. ## Acceptance criteria - Session cookie sets Secure and HttpOnly attributes in production - Session cookie sets SameSite in production to prevent cross-site send ## Explicitly out of scope - Token generation (E05-S02-T01) - Lookup hash storage (E05-S02-T02) - Logout revocation and expiration (E05-S02-T04/T05) - Admin API 401 to anonymous caller (E05-S02-T06) ## Test plan - Automated test checks the Set-Cookie header under production config ## Rollback note - Revert cookie attribute change and redeploy previous build ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 1 milestone 2026-08-27 00:17:18 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 00:17:18 +00:00
Sign in to join this conversation.