Install the Signed Cookies integration
Install the Signed Cookies Hash Generator and Hash Validator from Azion Marketplace and run them on an application to detect tampered cookies.
Signed Cookies protects the cookies you list against changes made on the client side. It is two integrations that run on the same application, and both are among the Marketplace integrations. In the response phase, the Hash Generator appends an encrypted version of each listed cookie to the response. In the request phase, the Hash Validator checks the cookies against their encrypted versions and adds violation headers to the request when they differ.
A signed cookie lets your application verify that no third party altered the session data, which defends against session hijacking. Seven objects must exist before a request is checked: the two installed functions, an application with the Functions and Application Accelerator modules turned on, one function instance per integration, and one Rules Engine rule per instance.
Prerequisites
- An Azion account. To sign in, refer to How to access Azion Console.
- An application served by a workload. To create one, refer to Applications quickstart.
- Turning on a product or a module can generate usage costs. For more information, refer to Pricing.
Install the integrations
Each install adds one function to your account: Signed Cookies - Hash Generator and Signed Cookies - Hash Validator. To install them from Azion Console:
Access Azion Console > Marketplace.
Enter Signed Cookies in the Search on Marketplace field, then select the Signed Cookies - Hash Generator card. Browsing the cards and the categories reaches the same page.
Return to Marketplace, select the Signed Cookies - Hash Validator card, then select Install.
Each card shows Successfully installed! and Latest version installed!, and both functions appear in the Function list of the Create Instance drawer.
Turn on the Functions module
An application runs an installed function only when its Functions module is on. The rule that runs the Hash Validator also uses the Forward Cookies behavior, which requires the Application Accelerator module. To turn on both modules:
Access Azion Console > Applications > your application.
In the Main Settings tab, go to the Modules section.
Azion Console confirms that the application was updated.
Create the function instances
Each integration needs its own function instance with its own arguments. The Hash Generator runs in the response phase and the Hash Validator in the request phase. To create the two instances in your application:
In Applications, select your application, then select the Functions Instances tab.
An application with no instance yet offers the same action as Function Instance. The Create Instance drawer opens.
In Name, enter a unique name that identifies the instance. For example: signed-cookies-generator.
In Function, select the Signed Cookies - Hash Generator function. The Arguments editor fills with the default arguments of the integration.
In Arguments, enter the Hash Generator arguments described below.
Repeat these steps with a name such as signed-cookies-validator, the Signed Cookies - Hash Validator function, and the Hash Validator arguments.
Both instances appear in the Functions Instances tab with the names you entered.
Hash Generator arguments
| Key | Description |
|---|---|
cookie_list | The cookies to protect. For each cookie in this list, an encrypted version of the cookie is appended to the response |
cookie_secret | A secret that protects the encrypted cookie against client-side manipulation |
tampering_cookie_prefix | The prefix of the names of the encrypted cookies |
The prefix sets the names of the encrypted cookies. With the value tampering_protection and the cookies yummy_cookie and tasty_cookie, the function creates tampering_protection_yummy_cookie and tampering_protection_tasty_cookie.
If tampering_cookie_prefix has no valid value, the function uses the default azion_tampering. The encrypted cookies are then azion_tampering_yummy_cookie and azion_tampering_tasty_cookie.
Hash Validator arguments
The Hash Validator takes the same keys as the Hash Generator, plus tampering_violation_header_prefix. This key sets the prefix of the headers the function appends to the request when it detects a cookie violation.
With the value Cookie-Violation, the function creates the Cookie-Violation-Any, Cookie-Violation-Counter, and Cookie-Violation-List headers. If the key has no valid value, the defaults are Azion-Tampering-Violation-Any, Azion-Tampering-Violation-Counter, and Azion-Tampering-Violation-List.
Create the rules
Each instance runs only when a Rules Engine rule calls it. The Hash Generator rule runs in the response phase. The Hash Validator rule runs in the request phase and adds the Forward Cookies behavior, which requires the Application Accelerator module. Both rules below match every request. To create the rules:
In Applications, select your application, then select the Rules Engine tab.
In Name, enter a name for the rule. For example: Sign cookies on every response.
In the Phase section, select Response Phase.
In the Criteria section, keep the ${uri} variable and the starts with operator, then enter / as the argument.
In the Behaviors section, select Run Function, then select the Hash Generator instance by its name.
Select + Rule again. Enter a name, select Request Phase, and set the same criterion.
In the Behaviors section, select Run Function, then select the Hash Validator instance by its name.
Select Add Behavior, then select Forward Cookies.
The Rules Engine tab lists one rule under the response phase and one under the request phase. A request whose protected cookies were altered reaches your application with the violation headers.
For every criterion and behavior a rule accepts, refer to Rules Engine.