Cookies · Practical guide

Secure, HttpOnly and SameSite cookies explained

Cookie attributes solve separate problems. A cookie can be limited to secure transport, hidden from JavaScript and restricted in cross-site requests. Reviewing those choices is especially useful for sessions, but a public header scan only sees cookies set by the response it receives.

Know what each attribute controls

Secure restricts cookie transmission to secure connections, with a localhost exception in browsers. HttpOnly prevents access through JavaScript cookie APIs, while the browser can still include the cookie in requests. SameSite controls when a cookie accompanies cross-site requests.

SameSite=Strict is restrictive; Lax allows some cross-site navigation. None permits cross-site use and requires Secure. These settings do not replace authorization checks or a CSRF strategy. Choose them according to the role of each cookie.

Reference: MDN: Set-Cookie

Use a session example as a review prompt

This example shows a session cookie whose value is deliberately a placeholder. It illustrates the attributes you might inspect, not a universal session configuration. Your framework should generate the actual session value.

Before copying a policy, list the journeys that cross a site boundary. External sign-in, payment callbacks and embedded applications deserve an explicit test. Also identify cookies that JavaScript intentionally reads: applying HttpOnly to those would change their behavior.

Set-Cookie: session=example-value; Path=/; Secure; HttpOnly; SameSite=Lax

Understand which cookies a scan can see

HeaderScan checks the final response without sending cookies or running JavaScript. If your session cookie is created only after login, it may not appear on a homepage scan. Likewise, cookies created by a script are outside this response-header check.

A clean public report is therefore not a review of every cookie in your application. Inspect your own authenticated session in browser developer tools and compare the attributes there. Keep real session values out of tickets, screenshots and shared debugging messages.

Keep reading

Related guides