web: clearing a cookie carries the attributes that set it !253

merged merged by cmc on 2026-09-05 00:02 UTC · krz/gitbay:sonar-cookie-attrs into main

Discussion

cmc

Stacked on !252. Four findings (go:S2092 ×2, go:S3330 ×2), one two-line change.

Logout and flash consumption expired their cookies with a bare Set-Cookie while the setting calls specify HttpOnly, SameSite and a Secure that follows TLS. Deletion works either way — a cookie is identified by name, domain and path, not by its flags — so this is consistency, not a live bug.

Secure still follows TLS rather than being forced on. An instance serving plain HTTP is supported, and a Secure cookie there is one the browser will not send back — which for a clearing cookie means one it never expires. That distinction is why the other two S2092 findings, on the setting calls, are dismissed rather than fixed.

Ref #153

retargeted from sonar-runner-workdir to main: !252 merged

2026-09-05 00:02 UTC