bk99.de entertain the web since 1997

RFC 6265: HTTP cookies: State on the web

Summary

RFC 6265 unifies cookie syntax and browser behaviour for session-related state over HTTP. Automatically attached state makes applications easier and increases CSRF and tracking risks. Secure defaults matter more than policies added later.

Ideas

  • Servers set name-value pairs with a scope.
  • Browsers automatically send matching cookies back.
  • Secure, HttpOnly and SameSite limit different risks.

Facts

  • RFC 6265 replaces RFC 2965.

Remarks

  • RFC 6265 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Set Secure, HttpOnly and a restrictive SameSite.
  • Keep lifetime and domain scope as small as possible.

References

Read the RFC at the RFC Editor

Search the Web Archive