Closes #20222: Enable HttpOnly flag for the CSRF cookie #1325

Closed
opened 2026-04-05 23:25:48 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @jetomit on 9/5/2025

Fixes: #20222

This prevents JS code from reading the CSRF token from the cookie store. If needed, the window.CSRF_TOKEN property can be used instead (see also commit cdea302).

Actual security benefit of this change is minimal, but it is sometimes requested by auditors.

*Originally created by @jetomit on 9/5/2025* <!-- Thank you for your interest in contributing to NetBox! Please note that our contribution policy requires that a feature request or bug report be approved and assigned prior to opening a pull request. This helps avoid waste time and effort on a proposed change that we might not be able to accept. IF YOUR PULL REQUEST DOES NOT REFERENCE AN ISSUE WHICH HAS BEEN ASSIGNED TO YOU, IT WILL BE CLOSED AUTOMATICALLY. Please specify your assigned issue number on the line below. --> ### Fixes: #20222 <!-- Please include a summary of the proposed changes below. --> This prevents JS code from reading the CSRF token from the cookie store. If needed, the `window.CSRF_TOKEN` property can be used instead (see also commit cdea302). Actual security benefit of this change is minimal, but it is sometimes requested by auditors.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/netbox#1325