Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring Session cookie policy: SameSite, Secure and the reverse proxy

Last updated: 1 Oct 20264 min read
tutorial
IntermediateBy AITrove Editorial

A shared session repository does not set the browser's cookie policy; the cookie still determines when a session ID crosses requests.

Treat the cookie as a bearer credential

Anyone holding the parcel-console session ID may act as its owner until the server rejects it. Set Secure on HTTPS deployments, HttpOnly to block script reads, and a SameSite policy that fits the login flow. A host-only cookie usually has a smaller exposure surface than a cookie shared with every subdomain. CSRF protection remains relevant when a browser sends the cookie automatically.

Account for proxy termination

If TLS ends at a trusted reverse proxy, the app may observe an internal HTTP hop. Configure forwarded-header handling only for headers supplied by that proxy, then verify the outgoing Set-Cookie contains Secure. Trusting arbitrary forwarded headers can let a client influence scheme and host decisions. The forwarding boundary and session rotation after login deserve a combined test.

Exercise the browser path

Sign in through the public HTTPS origin, inspect the cookie attributes, make a cross-site POST, and verify the session is rotated after authentication. Test a callback from the configured identity provider separately: an overstrict SameSite choice may break the intended redirect flow. The serializer sketch fixes policy for one deployment; domain and path must match the actual public origin.

Implementation sketch

Java
@Bean
DefaultCookieSerializer parcelSessionCookie() {
    DefaultCookieSerializer cookie = new DefaultCookieSerializer();
    cookie.setCookieName("PARCEL_SESSION");
    cookie.setUseSecureCookie(true);
    cookie.setUseHttpOnlyCookie(true);
    cookie.setSameSite("Lax");
    return cookie;
}

Cost and verification

Cookie flags have negligible server cost. A broad domain or long lifetime increases exposure if a session ID leaks; shorter idle time increases login frequency.

Common Mistakes

  • Do not set SameSite to None without requiring Secure and testing the actual browser flow.
  • Do not derive cookie security from an untrusted forwarded scheme.
  • Do not confuse HttpOnly with CSRF protection.

Read next

Spring Session Redis across replicas: shared login state has a Redis failure boundary, Spring Security CSRF: protect cookie-authenticated writes, Spring behind a proxy: trust forwarded headers only after the edge strips them, Spring Security login session: rotate the identifier at authentication.

spring
spring-security
session-cookie-policy
Storage details