A shared session repository does not set the browser's cookie policy; the cookie still determines when a session ID crosses requests.
Spring Session cookie policy: SameSite, Secure and the reverse proxy
Treat the cookie as a bearer credential
Anyone holding the parcel-console session ID may act as its owner until the server rejects it. Set Secure on HTTPS deployments, HttpOnly to block script reads, and a SameSite policy that fits the login flow. A host-only cookie usually has a smaller exposure surface than a cookie shared with every subdomain. CSRF protection remains relevant when a browser sends the cookie automatically.
Account for proxy termination
If TLS ends at a trusted reverse proxy, the app may observe an internal HTTP hop. Configure forwarded-header handling only for headers supplied by that proxy, then verify the outgoing Set-Cookie contains Secure. Trusting arbitrary forwarded headers can let a client influence scheme and host decisions. The forwarding boundary and session rotation after login deserve a combined test.
Exercise the browser path
Sign in through the public HTTPS origin, inspect the cookie attributes, make a cross-site POST, and verify the session is rotated after authentication. Test a callback from the configured identity provider separately: an overstrict SameSite choice may break the intended redirect flow. The serializer sketch fixes policy for one deployment; domain and path must match the actual public origin.
Implementation sketch
@Bean
DefaultCookieSerializer parcelSessionCookie() {
DefaultCookieSerializer cookie = new DefaultCookieSerializer();
cookie.setCookieName("PARCEL_SESSION");
cookie.setUseSecureCookie(true);
cookie.setUseHttpOnlyCookie(true);
cookie.setSameSite("Lax");
return cookie;
}Cost and verification
Cookie flags have negligible server cost. A broad domain or long lifetime increases exposure if a session ID leaks; shorter idle time increases login frequency.
Common Mistakes
- Do not set SameSite to None without requiring Secure and testing the actual browser flow.
- Do not derive cookie security from an untrusted forwarded scheme.
- Do not confuse HttpOnly with CSRF protection.
Read next
Spring Session Redis across replicas: shared login state has a Redis failure boundary, Spring Security CSRF: protect cookie-authenticated writes, Spring behind a proxy: trust forwarded headers only after the edge strips them, Spring Security login session: rotate the identifier at authentication.
