Lazo Lab Sign up

Web Security / Sessions and logins

Lesson 13 of 27

Cookies

Cookies keep you logged in. Protect session cookies with HttpOnly (JavaScript can't read them), Secure (HTTPS only) and SameSite (limits cross-site sending).

Key points

  • HttpOnly blocks script access
  • Secure: HTTPS only
  • SameSite=Lax is a good default
Set-Cookie: session=...; HttpOnly; Secure; SameSite=Lax
Watch a video on thisOpens YouTube search results for “Cookies” in a new tab

Quiz · +10 XP

Which cookie flag stops JavaScript from reading it?

Log in to save progress and earn XP.