In internal/service/auth/auth.go, the session cookie store is configured without Secure: true. The webhook URL in HandleAppDetail uses https:// prefix, indicating the app is expected to run behind HTTPS. Without the Secure flag, the session cookie will be sent over plain HTTP connections, exposing it to network sniffing.
Impact
Session hijacking via network interception when any HTTP (non-HTTPS) request is made.
Set Secure: true in the cookie options. Optionally make it configurable for development environments.
## Description
In `internal/service/auth/auth.go`, the session cookie store is configured without `Secure: true`. The webhook URL in `HandleAppDetail` uses `https://` prefix, indicating the app is expected to run behind HTTPS. Without the Secure flag, the session cookie will be sent over plain HTTP connections, exposing it to network sniffing.
## Impact
Session hijacking via network interception when any HTTP (non-HTTPS) request is made.
## Location
`internal/service/auth/auth.go` - `New()` function, `store.Options`
## Fix
Set `Secure: true` in the cookie options. Optionally make it configurable for development environments.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In
internal/service/auth/auth.go, the session cookie store is configured withoutSecure: true. The webhook URL inHandleAppDetailuseshttps://prefix, indicating the app is expected to run behind HTTPS. Without the Secure flag, the session cookie will be sent over plain HTTP connections, exposing it to network sniffing.Impact
Session hijacking via network interception when any HTTP (non-HTTPS) request is made.
Location
internal/service/auth/auth.go-New()function,store.OptionsFix
Set
Secure: truein the cookie options. Optionally make it configurable for development environments.