Express Trust Proxy: Does it Implicitly Enforce Secure Cookies Without secure:true?
29K reputation · 02 Dec 2020, 02:06 UTC
Goal
Determine whether an Express application that sets app.set('trust proxy', true) automatically treats all cookies as secure when the request arrives over HTTPS via a reverse proxy, even if the cookie options omit secure:true.
Context
When trust proxy is enabled, Express marks req.secure true if the X-Forwarded-Proto header equals https. The cookieParser middleware then attaches cookies to the request, and the Set-Cookie header is generated based on the cookie options. However, the Express documentation does not clarify whether a cookie lacking an explicit secure:true flag should be considered secure under this configuration.
Uncertainty
The behavior is ambiguous: is the secure flag automatically applied when trust proxy is true, or must developers explicitly set secure:true in each cookie? This distinction is critical for preventing cookie theft in production deployments that rely on HTTPS termination at a load balancer.
Questions
- When
trust proxyis true andX-Forwarded-Protoishttps, does Express set the secure flag on cookies that lack an explicitsecure:trueoption? - If not, is there any Express version or configuration where this implicit behavior is enabled?
- What is the recommended practice to guarantee secure cookie transmission behind a proxy?