Loading

Security Scans Indicate HttpOnly Attribute Not Set for XSRF-TOKEN Cookies

Дата публикации: Feb 24, 2026
Описание
When performing a security scan of the computer running Tableau Server, the scan results might state that XSRF-TOKEN cookies for the site do not have the HttpOnly attribute set.

Cause

​For protection, the session_id cookie has HttpOnly in place. Authentication cannot be completed with the XSRF-TOKEN alone and is successful only when XSRF-TOKEN is paired with the protected session_id cookie. 
Решение
No action necessary, this behavior is by design.
Дополнительные ресурсы
See Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet at the Open Web Application Security Project for more information about Double Submit Cookies.

Номер статьи базы знаний

001473061

 
Загрузка
Salesforce Help | Article