Why this matters
Proper cookie settings reduce session attacks and align with SOC 2.
Configure CookiePolicyOptions to enforce SameSite=Lax or Strict, HttpOnly, and Secure for all auth cookies.
Proper cookie settings reduce session attacks and align with SOC 2.
Side-by-side examples engineers can pattern-match during review.
options.MinimumSameSitePolicy = SameSiteMode.None;options.MinimumSameSitePolicy = SameSiteMode.Lax; app.UseCookiePolicy(options);options.HttpOnly = HttpOnlyPolicy.Always;options.Secure = CookieSecurePolicy.None;From the same buckets as this rule.
Public services must require TLSv1.2 or higher and set HSTS (max-age ≥ 15552000, includeSubDomains). Reject plaintext HTTP and weak ciphers; cookies must be Secure and HttpOnly with SameSite set.