IBM Support

LI80555: VISIT DEVELOPER PORTAL WITHOUT LOGIN, CLICK SUBSCRIBE IN PUBLIC PRODUCT THE HTTP 302 "SET-COOKIE" HEADER HAS NO SECURE FLAG

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Visit developer portal without login, click subscribe in public
    product, the HTTP 302 redirect request "Set-Cookie" header has
    no secure flag.
    
    Steps leading to the issue:
    Go to Developer Portal without login, API Products -> click
    "Subscribe". Developer Portal return HTTP 302 redirect and in
    its response contain "Set-Cookie" header without secure flag.
    For example:
    Set-Cookie: Drupal.visitor.startSubscriptionWizard=8;
    expires=Fri, 10-Jan-2020 09:25:13 GMT;
    
    Although the cookies is not set with secure flag, there is no
    security exposure since it doesn't contains any confidential
    information.
    

Local fix

Problem summary

  • The cookie used in the developer portal to allow redirection to
    current page when logging in as part of the subscription wizard
    did not have the secure flag set.
    

Problem conclusion

  • The cookie used to redirect anonymous users back to where they
    were when logging in as part of the subscription wizard in the
    developer portal did not contain any confidential information,
    purely a page reference, but it did not have the secure flag
    set. That has now been fixed and it is now both Secure and
    httpOnly.
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI80555

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    18X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-01-19

  • Closed date

    2019-02-01

  • Last modified date

    2019-02-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

  • R18X PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18X","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 September 2021