RFC 6265: HTTP cookies: State on the web
Summary
RFC 6265 unifies cookie syntax and browser behaviour for session-related state over HTTP. Automatically attached state makes applications easier and increases CSRF and tracking risks. Secure defaults matter more than policies added later.
Ideas
- Servers set name-value pairs with a scope.
- Browsers automatically send matching cookies back.
- Secure, HttpOnly and SameSite limit different risks.
Facts
- RFC 6265 replaces RFC 2965.
Remarks
- RFC 6265 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Set Secure, HttpOnly and a restrictive SameSite.
- Keep lifetime and domain scope as small as possible.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.