Loading

Security Scans Indicate HttpOnly Attribute Not Set for XSRF-TOKEN Cookies

Publiseringsdato: Feb 24, 2026
Beskrivelse
When performing a security scan of the computer running Tableau Server, the scan results might state that XSRF-TOKEN cookies for the site do not have the HttpOnly attribute set.

Cause

​For protection, the session_id cookie has HttpOnly in place. Authentication cannot be completed with the XSRF-TOKEN alone and is successful only when XSRF-TOKEN is paired with the protected session_id cookie. 
Løsning
No action necessary, this behavior is by design.
Flere ressurser
See Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet at the Open Web Application Security Project for more information about Double Submit Cookies.

Knowledge-artikkelnummer

001473061

 
Laster
Salesforce Help | Article