security.authentication

Avoid permissive Express session cookie scope

Express session cookies should not explicitly opt into cross-site or wildcard-style scope.

#Metadata

#Why it matters

Broad cookie scope increases where session cookies are sent and makes cross-site misuse harder to contain.

#Remediation

Prefer exact cookie domains and `SameSite=Lax` or `Strict` unless a reviewed cross-site requirement exists.

#Repository path

The generated metadata points to critiq-rules/libs/rules/catalog/rules/typescript/ts.security.express-permissive-cookie-config.rule.yaml.