Cookie types
What Are HttpOnly Cookies?
HttpOnly cookies are cookies that scripts running in the browser cannot directly read or change through JavaScript cookie APIs. The website’s server applies this restriction using the HttpOnly attribute.
They are especially useful for authentication. A login cookie may contain an identifier that allows the server to recognize a signed-in user. If a malicious script is injected into the page, HttpOnly helps prevent it from extracting that identifier through document.cookie.
The website can still use the cookie:
The server sets the cookie with HttpOnly.
The browser stores it.
The browser includes it in eligible requests to the server, without exposing its value to page scripts.
Despite its name, HttpOnly does not mean “use unencrypted HTTP.” An HttpOnly cookie can—and commonly should—also have the Secure attribute.
It is not a complete defence against malicious scripts: they may still trigger actions from the compromised page. OWASP’s session-management guidance explains this limitation.
Türkçe
English