Stacked on !252. Four findings (go:S2092 ×2, go:S3330 ×2), one
two-line change.
Logout and flash consumption expired their cookies with a bare
Set-Cookie while the setting calls specify HttpOnly, SameSite and a
Secure that follows TLS. Deletion works either way — a cookie is
identified by name, domain and path, not by its flags — so this is
consistency, not a live bug.
Secure still follows TLS rather than being forced on. An instance
serving plain HTTP is supported, and a Secure cookie there is one the
browser will not send back — which for a clearing cookie means one it
never expires. That distinction is why the other two S2092 findings, on
the setting calls, are dismissed rather than fixed.
Ref #153
retargeted from sonar-runner-workdir to main: !252 merged
2026-09-05 00:02 UTC