> There is already an upstream bug for this problem located at this url: > https://issues.jenkins-ci.org/browse/JENKINS-25019 > with a proposed fix that only adresses the HttpOnly issue for Tomcat. Why isn't the missing “secure” flag a Tomcat configuration issue?