My Oracle Support Banner

HttpOnly Flag Being Sent to Applet When SAML2IdentityAsserter is Used (Doc ID 2054640.1)

Last updated on AUGUST 31, 2020

Applies to:

Oracle WebLogic Server - Version 10.3 and later
Information in this document applies to any platform.

Goal

Why does WebLogic Server append the HttpOnly flag to the response when using the SAML2IdentityAsserter, even though the cookie-http-only property is set to false in application's deployment descriptor?

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.