Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


    Cloudron Forum

    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular

    Solved Secure cookies & X-Frame-Options

    Surfer
    5
    6
    333
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • luckow
      luckow translator last edited by

      To get 100 points with https://siwecos.de/en/, I need two more options. Do you have any idea how to set the following options in Surfer?

      • secure cookies: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
      • X-Frame-Options:
        https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options

      Pronouns: he/him | Primary language: German

      nebulon scooke 2 Replies Last reply Reply Quote 0
      • nebulon
        nebulon Staff @luckow last edited by

        @luckow what is missing regarding the cookie here?

        For x-frame-options, this is obsolete and now done via CSP, see https://docs.cloudron.io/apps/#custom-csp how to configure that.

        S jimcavoli 2 Replies Last reply Reply Quote 2
        • S
          sanduhrs @nebulon last edited by

          @nebulon The cookies that are set aren't marked as secure.
          siwecos-set-cookie.png

          Please also see: https://siwecos.de/wiki/Set-Cookie/EN

          1 Reply Last reply Reply Quote 0
          • jimcavoli
            jimcavoli App Dev @nebulon last edited by

            @nebulon Also while X-Frame-Options is not as current as CSP, it's still considered best practice to get more complete coverage for that protection across browsers, especially older ones:

            https://caniuse.com/contentsecuritypolicy2
            https://caniuse.com/x-frame-options

            At least, that's still the case for every audit and best practice list in the circles I'm in. It is still required by the latest ASVS 4.0.2 (criteria 14.4.7) as well (source: en / de). So I'd encourage both. While you're touching the session cookie, you can also probably go SameSite=Strict as well.

            nebulon 1 Reply Last reply Reply Quote 0
            • nebulon
              nebulon Staff @jimcavoli last edited by

              I've published a new app package which now has strict and secure cookies.

              Regarding the X-Frame-Options, we used to have that in the platform but decided against supporting it, due to the overlap with CSP and thus having caused inconsistency and confusion depending on what the app sets on its own.

              1 Reply Last reply Reply Quote 0
              • scooke
                scooke @luckow last edited by

                @luckow Thanks for introducing me to this site (siwecos.de)!

                A life lived in fear is a life half-lived

                1 Reply Last reply Reply Quote 2
                • First post
                  Last post
                Powered by NodeBB