From b92f34eb296fa371f3c5934ae6d07940016aa3a2 Mon Sep 17 00:00:00 2001 From: Dave Wichers Date: Wed, 4 Feb 2026 14:23:29 -0500 Subject: [PATCH] Potential fix for code scanning alert no. 49: Failure to use secure cookies Fix secure flag in Benchmark00087 Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .../java/org/owasp/benchmark/testcode/Benchmark00087.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/main/java/org/owasp/benchmark/testcode/Benchmark00087.java b/src/main/java/org/owasp/benchmark/testcode/Benchmark00087.java index ca188b0..da19371 100644 --- a/src/main/java/org/owasp/benchmark/testcode/Benchmark00087.java +++ b/src/main/java/org/owasp/benchmark/testcode/Benchmark00087.java @@ -88,7 +88,7 @@ public void doPost(HttpServletRequest request, HttpServletResponse response) if ("".equals(str)) str = "No cookie value supplied"; javax.servlet.http.Cookie cookie = new javax.servlet.http.Cookie("SomeCookie", str); - cookie.setSecure(false); + cookie.setSecure(true); cookie.setHttpOnly(true); cookie.setPath(request.getRequestURI()); // i.e., set path to JUST this servlet // e.g., /benchmark/sql-01/Benchmark01001 @@ -98,6 +98,6 @@ public void doPost(HttpServletRequest request, HttpServletResponse response) .println( "Created cookie: 'SomeCookie': with value: '" + org.owasp.esapi.ESAPI.encoder().encodeForHTML(str) - + "' and secure flag set to: false"); + + "' and secure flag set to: true"); } }