Fix cookie set without its protective attributes in Koa
A cookie is written without `httpOnly`, `secure`, or `sameSite`. Missing `httpOnly` turns any cross-site scripting bug into session theft; missing `secure` sends the cookie over plain HTTP; missing `sameSite` attaches it to cross-site requests. A cookie holding no sensitive value may not need all three, which is why the finding names the ones it did not find rather than assuming the worst.
medium likely Koa CWE-614 / OWASP A05:2021
The vulnerable pattern in Koa
This finding comes from the Koa fixture in the owlwarden test suite. This cookie is missing protections: httpOnly keeps the cookie out of reach of JavaScript, so a cross-site scripting bug cannot read the session; secure stops the cookie being sent over plain HTTP; sameSite stops the browser attaching the cookie to cross-site requests.
The corrected handler
Pass the attributes to ctx.cookies.set.
ctx.cookies.set('session', token, {
httpOnly: true,
secure: process.env.NODE_ENV === 'production',
sameSite: 'lax',
})
If you are not using Koa
Set httpOnly, secure, and sameSite when writing a cookie that carries anything the user would not want read or replayed.
Check your own repository
npx owlwarden scan
npx owlwarden explain insecure-cookie
Runs on your machine. No account, no telemetry, no network unless you ask. In CI, SARIF uploads to code scanning and the exit code is the gate.
Other Koa checks
Rules with a tested Koa example.
- cors-permissive medium Cross-origin policy accepts any origin
- hardcoded-secret high Credential hardcoded in source
- install-lifecycle-script medium Package declares an install-time script
- open-redirect medium Redirect target comes from the caller
- security-headers-missing medium Security headers are not configured
- sensitive-data-logged medium Sensitive data written to a log
- sql-injection high SQL query built by string interpolation
- ssrf high Server fetches a URL the caller controls
- stack-trace-leak high Stack trace leaked in error response
- weak-crypto high Broken cryptographic primitive protecting a secret