Serve all traffic over HTTPS and set Secure, HttpOnly, and SameSite attributes on session and auth cookies.
Why This Matters
Plaintext transport and lax cookie flags expose sessions to interception and theft (OWASP A02/A05).
Related Rules
Catch this automatically on every PR
BeforeMerge scans your pull requests against this rule and dozens more. Get actionable feedback before code ships.