<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Secure cookies &amp; X-Frame-Options]]></title><description><![CDATA[<p dir="auto">To get 100 points with <a href="https://siwecos.de/en/" target="_blank" rel="noopener noreferrer nofollow ugc">https://siwecos.de/en/</a>, I need two more options. Do you have any idea how to set the following options in Surfer?</p>
<ul>
<li>secure cookies: <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies" target="_blank" rel="noopener noreferrer nofollow ugc">https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies</a></li>
<li>X-Frame-Options:<br />
<a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options" target="_blank" rel="noopener noreferrer nofollow ugc">https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/topic/5624/secure-cookies-x-frame-options</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 19:12:43 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/5624.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 06 Sep 2021 10:35:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Secure cookies &amp; X-Frame-Options on Wed, 08 Sep 2021 14:25:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a> Thanks for introducing me to this site (<a href="http://siwecos.de" target="_blank" rel="noopener noreferrer nofollow ugc">siwecos.de</a>)!</p>
]]></description><link>https://forum.cloudron.io/post/36228</link><guid isPermaLink="true">https://forum.cloudron.io/post/36228</guid><dc:creator><![CDATA[scooke]]></dc:creator><pubDate>Wed, 08 Sep 2021 14:25:54 GMT</pubDate></item><item><title><![CDATA[Reply to Secure cookies &amp; X-Frame-Options on Wed, 08 Sep 2021 11:42:55 GMT]]></title><description><![CDATA[<p dir="auto">I've published a new app package which now has strict and secure cookies.</p>
<p dir="auto">Regarding the X-Frame-Options, we used to have that in the platform but decided against supporting it, due to the overlap with CSP and thus having caused inconsistency and confusion depending on what the app sets on its own.</p>
]]></description><link>https://forum.cloudron.io/post/36220</link><guid isPermaLink="true">https://forum.cloudron.io/post/36220</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Wed, 08 Sep 2021 11:42:55 GMT</pubDate></item><item><title><![CDATA[Reply to Secure cookies &amp; X-Frame-Options on Wed, 08 Sep 2021 10:07:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Also while X-Frame-Options is not as current as CSP, it's still considered best practice to get more complete coverage for that protection across browsers, especially older ones:</p>
<p dir="auto"><a href="https://caniuse.com/contentsecuritypolicy2" target="_blank" rel="noopener noreferrer nofollow ugc">https://caniuse.com/contentsecuritypolicy2</a><br />
<a href="https://caniuse.com/x-frame-options" target="_blank" rel="noopener noreferrer nofollow ugc">https://caniuse.com/x-frame-options</a></p>
<p dir="auto">At least, that's still the case for every audit and best practice list in the circles I'm in. It is still required by the latest <a href="https://owasp.org/www-project-application-security-verification-standard/" target="_blank" rel="noopener noreferrer nofollow ugc">ASVS</a> 4.0.2 (criteria 14.4.7) as well (source: <a href="https://github.com/OWASP/ASVS/raw/v4.0.2/4.0/OWASP%20Application%20Security%20Verification%20Standard%204.0.2-en.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">en</a> / <a href="https://github.com/OWASP/ASVS/raw/v4.0.2/4.0/OWASP%20Application%20Security%20Verification%20Standard%204.0.2-de.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">de</a>). So I'd encourage both. While you're touching the session cookie, you can also probably go SameSite=Strict as well.</p>
]]></description><link>https://forum.cloudron.io/post/36214</link><guid isPermaLink="true">https://forum.cloudron.io/post/36214</guid><dc:creator><![CDATA[jimcavoli]]></dc:creator><pubDate>Wed, 08 Sep 2021 10:07:52 GMT</pubDate></item><item><title><![CDATA[Reply to Secure cookies &amp; X-Frame-Options on Mon, 06 Sep 2021 16:22:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> The cookies that are set aren't marked as secure.<br />
<img src="/assets/uploads/files/1630944936370-siwecos-set-cookie.png" alt="siwecos-set-cookie.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Please also see: <a href="https://siwecos.de/wiki/Set-Cookie/EN" target="_blank" rel="noopener noreferrer nofollow ugc">https://siwecos.de/wiki/Set-Cookie/EN</a></p>
]]></description><link>https://forum.cloudron.io/post/36141</link><guid isPermaLink="true">https://forum.cloudron.io/post/36141</guid><dc:creator><![CDATA[sanduhrs]]></dc:creator><pubDate>Mon, 06 Sep 2021 16:22:17 GMT</pubDate></item><item><title><![CDATA[Reply to Secure cookies &amp; X-Frame-Options on Mon, 06 Sep 2021 12:14:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a> what is missing regarding the cookie here?</p>
<p dir="auto">For x-frame-options, this is obsolete and now done via CSP, see <a href="https://docs.cloudron.io/apps/#custom-csp" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/apps/#custom-csp</a> how to configure that.</p>
]]></description><link>https://forum.cloudron.io/post/36126</link><guid isPermaLink="true">https://forum.cloudron.io/post/36126</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Mon, 06 Sep 2021 12:14:46 GMT</pubDate></item></channel></rss>