net/http.Cookie struct. Missing Secure, HttpOnly, or SameSite flags are security findings for session cookies.
.SetCookie().SetCookie()SinkSetCookie(w ResponseWriter, cookie *Cookie)
Sets HTTP cookie. Finding when cookie.Secure or cookie.HttpOnly is false for session cookies.
1| FQN | Field | |
|---|---|---|
| net/http.Cookie | fqns[0] |
Wrong FQN → 0 findings. Verify with: change fqns to garbage → must produce 0 results.
// standard library — no go.mod entry required
from codepathfinder.go_rule import GoHTTPCookie