Web Security / Sessions and logins
Lesson 13 of 27
Cookies
Cookies keep you logged in. Protect session cookies with HttpOnly (JavaScript can't read them), Secure (HTTPS only) and SameSite (limits cross-site sending).
Key points
- HttpOnly blocks script access
- Secure: HTTPS only
- SameSite=Lax is a good default
Set-Cookie: session=...; HttpOnly; Secure; SameSite=LaxQuiz · +10 XP
Which cookie flag stops JavaScript from reading it?
Log in to save progress and earn XP.