Every session or authentication cookie configured, set or served carries Secure, HttpOnly and an explicit SameSite.
Inputs
Code and configuration files of the checkout (express-session, cookie-session, iron-session, res.cookie and cookies().set with a session-like name, Set-Cookie headers, Django and Flask SESSION_COOKIE_* settings evaluated over all settings files, Starlette/FastAPI set_cookie, Laravel config/session.php, PHP setcookie); with a deployed origin, the Set-Cookie headers of its root response through the engine's outbound helper. Paths listed in excludes (test, spec and tmp files, __tests__, __mocks__, fixtures, test, tests and audit-scripts folders) are never analysed.
Decision rule
A session({...}) or cookieSession({...}) counts as the middleware call only when it is not a function or method definition (not preceded by async, function, get, set or *, and not followed by a body brace or an arrow) and its object carries at least one option of those middlewares (secret, keys, cookie, store, resave, saveUninitialized, name, maxAge, secure, httpOnly, sameSite, domain, path, expires): a callback declared as `async session({ session, token }) { … }` is a definition, its destructured parameter list is not a cookie configuration, and the trace names it. Not applicable when no session cookie is configured, set or served. FAIL when a session cookie lacks Secure (or sets it to false) or lacks HttpOnly (HIGH); a missing explicit SameSite is MEDIUM (blocks in Extended suites). Secure may be driven by configuration (an environment read) but never false; Django's HttpOnly and SameSite=Lax defaults count as set. PASS when every located cookie carries the three flags.
Type
deterministic
1.0.3: false positive of the attestation of platform/apps/auth (2026-09-24), fixed in the script: `session({...})` cuenta como llamada al middleware sólo si no es una DEFINICIÓN de función o método (ni precedida de async/function/get/set/*, ni seguida de un cuerpo o una flecha) y su objeto lleva alguna opción de express-session/cookie-session; el callback `async session({ session, token })` de next-auth se leía como una cookie sin flags. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).))