How to enable HTTP only flag for the cookies PS_LOGINLIST, PS_TOKENEXPIRE and ExpirePage in peopleso
Hi ,
Please suggest how we can enable http only flag for the cookies PS_LOGINLIST, PS_TOKENEXPIRE, ExpirePage .. etc.
As per Oracle document id 985574.1, "E-PIA: Does PeopleSoft PIA Support HTTPOnly for Cookies?" , PS_TOKEN cert cannot be set to HTTPOnly by design.
Just wanted to confirm whether HTTP only flag can be enabled for other session cookies like PS_LOGINLIST, PS_TOKENEXPIRE, ExpirePage ,HPTabName, HPTabNameRemote and SignOnDefault.
Http only flag is not enabled even after added <cookie-http-only> tag in weblogic.xml.
<cookie-http-only>true</cookie-http-only>
PeopleTools Release: 8.53.09
Oracle Weblogic 10.3.6.0.0
Thanks in advance for your suggestions.
Thanks,
Anbu G