State‑Saving Cookie Fallback: Unresolved Security Question
25K reputation · 30 Apr 2024, 19:07 UTC
Goal
Prevent accidental public exposure of user‑specific table state while using DataTables’ stateSave:true feature.
Constraints
DataTables 1.10+ stores state in localStorage by default. When localStorage is unavailable (e.g., privacy mode or disabled), the library silently falls back to a cookie containing the same JSON state. This fallback is not exposed through the public API, nor is there a documented warning about the risk of sending state data in a cookie on shared or public pages.
Unresolved Decision
Should DataTables provide a configurable option to force cookie usage, enforce secure cookie attributes, or explicitly warn developers about the potential for state leakage when stateSave is enabled on public or shared‑device contexts?
Specific Questions
- What mechanisms does DataTables use to detect
localStorageunavailability and trigger the cookie fallback? - Can developers programmatically override the fallback to enforce a particular storage method or cookie attribute set?
- Would adding a
stateStorageMethodoption or astateSaveWarningcallback improve security transparency?