What is behavior for cookie-http-only?

I noticed cookie-http-only property available in 9.2 and also 10.3 but what exactly does enabling this do?
The documentation isn't very clear.
"Specifies whether HttpOnly cookies are enabled. When this element is set to true, all session cookies would be unavailable to the browser scripts. The default value is true. Therefore, HttpOnly cookies are enabled by default."
Does that mean it will make my jsessionid as httponly? In 9.2, enabling this property didn't do this.
Does it just mean it will honor httponly settings? But that would be on the browser end.
Does it mean it will make my other session cookies as httponly and not jsession id?
Please clarify

Smart Mailboxes don't do anything to messages except list them. The messages must reside somewhere else. If the message is deleted from wherever it lives, or if it no longer satisfies the search criteria that define the Smart Mailbox, it will no longer appear. For example, suppose the Smart Mailbox specifies "unread" messages. Once the message has been read, it will not appear in that Smart Mailbox the next time it is opened.

Similar Messages

  • Arrowpoint cookie HTTP Only flag set.

    Hi All,
    I have a site running an application on which we have identified a vulnerability we wish to close. The CSS11501 is using the advance balance arrowpoint cookie method, however tests are showing that the HTTP only parameter is not set. I am unable to find a way of doing this at present. Does anyone know how to acheive this?
    Until I can do so there is a remote possibilty I am leaving my application open to cross site scripting attacks.
    Microsoft use the HTTPOnly cookie option which sets a HTTPOnly flag. he following url has some information for review.
    Thanks in advance for your help.
    Alfie...

    Alfie,
    your security test tool assume the CSS is a webserver and therefore complains when seeing some missing *flag*.
    However, you won't be able to attack the CSS with whatever method that works against a webserver.
    We have our own onboard DOS feature.
    So, there is no option to use this microsoft HTTPOnly flag because there is no need for it.
    Make sure the servers behind the CSS are protected and have your HTTPOnly flag.
    Gilles.

  • What is Behavior for Smart Mailbox message retention/deletion?

    When (how long) do Smart Mailboxes delete their mail? Mine seem to last only a day or a week. It's impossible to tell. I don't see anywhere that I can set the preference.
    Thanks

    Smart Mailboxes don't do anything to messages except list them. The messages must reside somewhere else. If the message is deleted from wherever it lives, or if it no longer satisfies the search criteria that define the Smart Mailbox, it will no longer appear. For example, suppose the Smart Mailbox specifies "unread" messages. Once the message has been read, it will not appear in that Smart Mailbox the next time it is opened.

  • Spotlight Search? What is it for?

    Tapping "Spotlight Search"  Gives me a list with things I can check mark  or uncheck mark ...are they important,?use a lot of data?

    Spotlight serch on the far right of the iPhone's homescreen allows the user to search for emails,contacts, music, Apps, podcasts, nots, events, videos, reminders, messages, voice memos. If you have alot of apps, data on you iPhone and fell lazy to look for it to the highest purpose, you can use spotlight to either type what your looking for (iPhone 4 and lower) or speak what your looking for (iPhone 4S ONLY) In for spotlight to work you have to go to spotlight search in the settings app, go to general and scroll to spotlight and checkmark or uncheck mark what you what it to search for. I hope this was found helpfull.
    -H

  • I plugged my iphone in for the first time to my itunes account and it now reads that this device is already  associated with an apple id.  what does that mean.  i only have one apple id. and do i chose cancel or transfer?

    i plugged my iphone in for the first time to my itunes account and it now reads that this device is already  associated with an apple id.  what does that mean.  i only have one apple id. and do i chose cancel or transfer?

    Hello there, Shellywms09.
    The following Knowledge Base article points out why you are receiving that message on your iPad:
    iTunes Store: Associating a device or computer to your Apple ID
    http://support.apple.com/kb/ht4627
    Thanks for reaching out to Apple Support Communities.
    Cheers,
    Pedro

  • Just because I have an imac pre 2007 why can I not order photo albums???!!  I spent hours building a photo album for my parents only to find out that because my mac is earlier than 2007, even though I have 10.6.8, I can no longer order?! What is that

    Just because I have an imac pre 2007 why can I not order photo albums???!!
    I spent hours building a photo album for my parents only to find out that because my mac is earlier than 2007, even though I have 10.6.8, I can no longer order?! What is with that? This makes no sense. I can go online to various "photo shop" place and regardless of the OS and computer I am working from I can order a photo album so why can I no longer do this through iPhoto on my MAC?
    How do I order my album now? If somebody could please explain as I am going home in 1 month and really wanted to surprise my aging parents with this book.

    I found this:
    http://store.apple.com/us/help/print_products
    Have you tried this?

  • TS1702 I purchased 2 packages of gems for skylanders and only received 1 package. Got email receipts and tried to report problem on ipad2 and it keeps coming up with to many https redirects. Can anyone help? Just want my gems :).

    I purchased 2 packages of gems for skylanders and only received 1 package. Got email receipts and tried to report problem with link in email on my ipad2 and it keeps coming up with to many https redirects. Can anyone help? Just want my gems :).

    Contact iTunes Customer Service and request assistance
    Use this Link  >  Apple  Support  iTunes Store  Contact

  • I've been sent a scan of a document as an attachment. Clicking on it, I get the message, "Pixel aspect ration correction is for preview purposes only. Turn it off for maximum image quality." What is pixel aspect ration and how do I turn it off?

    I've been sent a scan of a document as an attachment. Clicking on it, I get the message, "Pixel aspect ration correction is for preview purposes only. Turn it off for maximum image quality." What is pixel aspect ration and how do I turn it off?

    It's "aspect ratio", not aspect "ration". 
    It's what determines whether you have square pixels ("normal") or, if rectangular pixels, what the aspect ratio (width : length)  of that rectangle is.
    It's explained in the Help files.  I cannot go into more detail because you have neglected to provide information about your platform and exact version of Photoshop.
    Example in next post

  • I don't know what i need. I'am a mac user but i need to run quick books premier. This is the only software i need in windows 7. Could i have some advise in  what is better for me, Bootcamp or parallels

    I don't know what i need. I'am a mac user but i need to run quick books premier. This is the only software i need in windows . Could i have some advise in  what is better for me, Bootcamp or Parallels

    The Intuit rep said they don't "support" QuickbooksPremier on a "virtual machine." Do you know what I risk by using it, anyway? thanks for the advice about Boot Camp vs Parallels, BTW!
    I use QuickBooks Pro for Mac, so I haven't had need to try any of the Windows versions in a VM. But I can't think why it wouldn't work. From within the VM, QuickBooks Premier would believe it is operating on PC hardware within Windows.
    I would guess they mean that the multiple user support wouldn't work from within the VM. But I would think that would also work. Windows can see the Internet from within the VM, which means it can see your network. So if Windows can see the network, then QB Premier should be able to, too.
    I know you can get Parallels as a demo, and maybe you could get QB Premier as trial software. So if you already have a retail copy of Windows to load into a VM, it would only cost you time to test what's possible.

  • How to enable https or SSL for login page only?

    Hi,
    My application is runnnin in iPlanet web server 4.1 version.
    how to make my login page only secured (SSL)?
    previously we have done https enable for the whole application. but client specifically wants for login page only, not for the whole application. how can i make SSL for login page only in iPlanet 4.1.
    I searched through iPlanet console, but i didn't get any option such.
    i found one more thing console,i.e., "encrypt on or off". if i put encrypt "on" means, it will be for the whole application? How can i make it for login page only.
    Do i need to do any code changes for that?
    i tried through web.xml security constraints tags, but it is not working and taking that file as we are doing everything in servlet.properties and rules.properties files.
    can anybody help me in this regard?
    Regards,
    Chandu

    You specify SSL in web.xml of your application. So, in that case other web applications in same server would not be affected.
    <security-constraint>
    <web-resource-collection>
    <web-resource-name>myresources</web-resource-name>
    <url-pattern>/*</url-pattern>
    </web-resource-collection>
    <user-data-constraint>
    <transport-guarantee>CONFIDENTIAL</transport-guarantee>
    </user-data-constraint>
    </security-constraint>Following link will help you to setup SSL in tomcat:
    [http://techtracer.com/2007/09/12/setting-up-ssl-on-tomcat-in-3-easy-steps/|http://techtracer.com/2007/09/12/setting-up-ssl-on-tomcat-in-3-easy-steps/]
    Thanks,
    Mrityunjoy

  • I can't able to access shapes(circle,star) in tool,only rectangle is used.what to do for drawing other shapes?

    i can't able to access shapes(circle,star) in tool,only rectangle is used.what to do for drawing other shapes?

    Mylenium is right; we don't know enough to help you.
    Screenshots of your interface would help. Also, more information about your OS, version of AE, etc.: FAQ: What information should I provide?

  • I´m doing a design for presale, where I will need a router what support PAT for 500 or a little more of users, it not need any more features only static routing and dhcp pool for 500 users, can you help me for know what router recommend?

    I´m doing a design for presale, where  I will  need a router what support PAT for 500 or a little more of users, it  not need any more features only static routing and dhcp pool for 500 users, can you help me for know what router recommend?

    What is your WAN speed currently and projected WAN speed in the next 3 years?

  • Searching with the Search tab only looks in 3 of 19 merged chms, no matter what is searched for

    I'm using RoboHelp 8.  I'm using the Search tab in the HTML Help window to search.  Although it finds what I’m searching for, it only looks in 3 of my 19 merged chm files, no matter what I search for.   I can tell by the Location column in the search results.
    Is there a known bug in HTML Help search capabilities?

    It would be worth checking that the window and single source layout properties of all 19 projects are setup exactly the same. Also make sure that there are no child CHM files in the project directory before you compile. RoboHelp insists that they are copied in when you add links but they can cause issues like this when you compile. When you compile there should be no other CHMs in the project directory.

  • In the top right corner of my i phone screen there is a small padlock with a circle around it, what is this for and how do i get rid of it,, it has only just popped up

    in the top right corner of my iphone screen there is a small padlock with a circle around it, what is this for and how do i get rid of it, it has just popped up...

    That is the orientation lock indicator. It means that you phone will not go into landscape mode when tilted on it's side.
    To turn orientation lock off double tap the home button, to access the multitasking menu, then swipe your finger to the right over the multitasking bar at the bottom and touch the big button on the left with the padlock.

  • What is the best product for using itunes only?

    I am considering buying a laptop / notebook / ipad or whatever for using itunes only.  The goal would be to add all cd's to the product and then increase my collection via downloads only going forward.
    Can anyone recommend the best product for this please?  I have an ipod nano and I'm new to the iphone, so I'm an Apple convert, although I'd consider a non-Apple product too (sorry Apple!).
    Budget is tight!
    Thanks in advance
    Rufus73

    Without a bit more info, it's hard to answer your question.
    How many CD's do you intend to keep on the PC/Mac/iPad as an iPad has a maximum storage of aprox 55Gb's for the top model, whereas even a basic PC laptop is likely to have 150Gb plus of space. Plus you are going to need a PC/Mac to copy the CD's in the first place, unless you intend to buy all your music from the iTunes store.
    For me I would look at either a MacBook if you can go to the £1000 price bracket, or look at a MacMini and cheap screen then transfer the music to your iPod/iPhone or sadly from a price point of view you may have to go the Windows route as a basic laptop will start at £400
    Mike

Maybe you are looking for