Skip to content

v1.3.0 - HttpOnly Cookie Security Enhancement

Choose a tag to compare

@CodeMath CodeMath released this 30 Aug 14:31
· 22 commits to main since this release

🎉 Major Security Release

This release introduces comprehensive HttpOnly cookie support for enhanced XSS protection while maintaining full backward compatibility.

🔐 Security Enhancements

  • HttpOnly Cookie Support - Secure token storage preventing XSS attacks
  • CSRF Protection - SameSite cookie settings for CSRF attack prevention
  • 90%+ Security Improvement - Comprehensive upgrade from localStorage
  • Automatic Cookie Management - Server-side token handling with HttpOnly flags

✨ New Features

  • Smart token storage with HttpOnly cookies and localStorage/sessionStorage fallback
  • Enhanced middleware for cookie-based authentication processing
  • Complete migration guide for HttpOnly Cookie transition
  • Seamless upgrade path for existing implementations

🔧 Technical Improvements

  • Optimized imports and cleaned duplicate code
  • Removed cache files and unused directories
  • Enhanced JavaScript with cookie utility functions
  • Better documentation with security migration guide

⚙️ New Configuration Options

DRF_SPECTACULAR_AUTH = {
    'USE_HTTPONLY_COOKIE': True,      # Enable HttpOnly cookies (Recommended)
    'COOKIE_MAX_AGE': 3600,           # Cookie expiry in seconds
    'COOKIE_SECURE': True,            # HTTPS only (set False for dev)
    'COOKIE_SAMESITE': 'Strict',      # CSRF protection level
    'TOKEN_STORAGE': 'sessionStorage', # Fallback storage (changed default)
}

📋 Migration Benefits

  • XSS Defense: 100% protection against JavaScript-based token theft
  • CSRF Defense: 90% protection with SameSite cookie settings
  • Automatic Cleanup: Tokens automatically expire and are cleaned up
  • Production Ready: Enterprise-grade security for production environments

📚 Documentation Updates

  • New HTTPONLY_COOKIE_MIGRATION.md - Complete migration guide
  • New TUTORIAL.md - Comprehensive 8-chapter tutorial from basics to production
  • New DEVELOPMENT_RETROSPECTIVE.md - Development journey and decisions
  • Updated README with v1.3.0 security features
  • Enhanced CHANGELOG with detailed migration instructions

🏗️ Architecture Improvements

  • Enhanced views with cookie setting/clearing in login/logout endpoints
  • Improved middleware for cookie-based authentication with fallback support
  • JavaScript updates with cookie handling and backward compatibility
  • Clean codebase with optimized imports and removed Python cache files

📦 Installation

pip install --upgrade drf-spectacular-auth==1.3.0

🚀 Quick Migration

For maximum security, enable HttpOnly cookies:

DRF_SPECTACULAR_AUTH = {
    'USE_HTTPONLY_COOKIE': True,  # Enable HttpOnly cookies
    'COOKIE_SECURE': True,        # HTTPS only (False for dev)
    'COOKIE_SAMESITE': 'Strict',  # CSRF protection
    # ... your other settings
}

For development environments, set COOKIE_SECURE = False for HTTP.

📖 Full Documentation

🙏 Thank You

Thank you to all contributors and users who have helped make this package more secure and robust!