<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Scans report &amp;quot;COOKIES WITHOUT HTTPONLY/SECURE FLAG SET&amp;quot; used by Dynatrace Synthetic (HTTP) monitors in Synthetic Monitoring</title>
    <link>https://community.dynatrace.com/t5/Synthetic-Monitoring/Security-Scans-report-quot-COOKIES-WITHOUT-HTTPONLY-SECURE-FLAG/m-p/284547#M3177</link>
    <description>&lt;P&gt;For browser monitors, if the browser monitors an application with RUM enabled, it will pick up this setting from the RUM application.&amp;nbsp;&lt;BR /&gt;For HTTP Monitors, I wouldn't expect any cookies to be set, as no browser is involved. Could you confirm which cookies you are referring to? This might be easier to answer in a chat/ support ticket, as you can then provide links to the relevant monitors.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Aug 2025 13:11:30 GMT</pubDate>
    <dc:creator>HannahM</dc:creator>
    <dc:date>2025-08-22T13:11:30Z</dc:date>
    <item>
      <title>Security Scans report "COOKIES WITHOUT HTTPONLY/SECURE FLAG SET" used by Dynatrace Synthetic (HTTP) monitors</title>
      <link>https://community.dynatrace.com/t5/Synthetic-Monitoring/Security-Scans-report-quot-COOKIES-WITHOUT-HTTPONLY-SECURE-FLAG/m-p/283365#M3158</link>
      <description>&lt;P&gt;My customer has reported that their security scans report "COOKIES WITHOUT HTTPONLY/SECURE FLAG SET" used by Dynatrace Synthetic (HTTP) monitors that they use.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that Dynatrace can't use HTTPOnly flags since JS can't work with this. But I should be able to set a Secure Cookie attribute for the synthetic monitor - This capability is nicely documented for Web applications (&lt;A href="https://docs.dynatrace.com/managed/shortlink/cookies#secure-cookies" target="_blank"&gt;https://docs.dynatrace.com/managed/shortlink/cookies#secure-cookies&lt;/A&gt;) but not for Synthetic monitors. I presume I can enable Cookies for the synthetic monitor via &lt;STRONG&gt;Monitor &amp;gt; Settings &amp;gt; General &amp;gt; Cookies&lt;/STRONG&gt; but the documentation (&lt;A href="https://docs.dynatrace.com/managed/shortlink/http-monitors-config#setup" target="_blank"&gt;https://docs.dynatrace.com/managed/shortlink/http-monitors-config#setup&lt;/A&gt;) doesn't provide clear instructions on how to do this.&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Francois&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 09:13:40 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Synthetic-Monitoring/Security-Scans-report-quot-COOKIES-WITHOUT-HTTPONLY-SECURE-FLAG/m-p/283365#M3158</guid>
      <dc:creator>francois_jouber</dc:creator>
      <dc:date>2025-08-08T09:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Security Scans report "COOKIES WITHOUT HTTPONLY/SECURE FLAG SET" used by Dynatrace Synthetic (HTTP) monitors</title>
      <link>https://community.dynatrace.com/t5/Synthetic-Monitoring/Security-Scans-report-quot-COOKIES-WITHOUT-HTTPONLY-SECURE-FLAG/m-p/284547#M3177</link>
      <description>&lt;P&gt;For browser monitors, if the browser monitors an application with RUM enabled, it will pick up this setting from the RUM application.&amp;nbsp;&lt;BR /&gt;For HTTP Monitors, I wouldn't expect any cookies to be set, as no browser is involved. Could you confirm which cookies you are referring to? This might be easier to answer in a chat/ support ticket, as you can then provide links to the relevant monitors.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 13:11:30 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Synthetic-Monitoring/Security-Scans-report-quot-COOKIES-WITHOUT-HTTPONLY-SECURE-FLAG/m-p/284547#M3177</guid>
      <dc:creator>HannahM</dc:creator>
      <dc:date>2025-08-22T13:11:30Z</dc:date>
    </item>
  </channel>
</rss>

