8 ms·
> It's more secure. If identifying session data is not accessible to JavaScript, it makes a site more secure from XSS attacks. HTTPOnly should take care of thi
by nsmartt 13y ago
> It's more secure. If identifying session data is not accessible to JavaScript, it makes a site more secure from XSS attacks.
HTTPOnly should take care of this.
- leokun 13y agoIt depends, HTTPOnly cookies are still accessible to JavaScript in some conditions, like those using an Android browser: https://www.owasp.org/index.php/HttpOnly#Browsers_Supporting_HttpOnly https://www.owasp.org/index.php/HttpOnly#Browsers_Supporting...