Loading

Security Scans Indicate HttpOnly Attribute Not Set for XSRF-TOKEN Cookies

Publiceringsdatum: Feb 24, 2026
Beskrivning
When performing a security scan of the computer running Tableau Server, the scan results might state that XSRF-TOKEN cookies for the site do not have the HttpOnly attribute set.

Cause

​For protection, the session_id cookie has HttpOnly in place. Authentication cannot be completed with the XSRF-TOKEN alone and is successful only when XSRF-TOKEN is paired with the protected session_id cookie. 
Lösning
No action necessary, this behavior is by design.
Ytterligare resurser
See Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet at the Open Web Application Security Project for more information about Double Submit Cookies.

Knowledge-artikelnummer

001473061

 
Laddar
Salesforce Help | Article