Cookies · Practical guide
Secure, HttpOnly and SameSite cookies explained
Cookie attributes solve separate problems. A cookie can be limited to secure transport, hidden from JavaScript and restricted in cross-site requests. Reviewing those choices is especially useful for sessions, but a public header scan only sees cookies set by the response it receives.
Know what each attribute controls
Secure restricts cookie transmission to secure connections, with a localhost exception in browsers. HttpOnly prevents access through JavaScript cookie APIs, while the browser can still include the cookie in requests. SameSite controls when a cookie accompanies cross-site requests.
SameSite=Strict is restrictive; Lax allows some cross-site navigation. None permits cross-site use and requires Secure. These settings do not replace authorization checks or a CSRF strategy. Choose them according to the role of each cookie.
Reference: MDN: Set-Cookie
Use a session example as a review prompt
This example shows a session cookie whose value is deliberately a placeholder. It illustrates the attributes you might inspect, not a universal session configuration. Your framework should generate the actual session value.
Before copying a policy, list the journeys that cross a site boundary. External sign-in, payment callbacks and embedded applications deserve an explicit test. Also identify cookies that JavaScript intentionally reads: applying HttpOnly to those would change their behavior.
Set-Cookie: session=example-value; Path=/; Secure; HttpOnly; SameSite=Lax Understand which cookies a scan can see
HeaderScan checks the final response without sending cookies or running JavaScript. If your session cookie is created only after login, it may not appear on a homepage scan. Likewise, cookies created by a script are outside this response-header check.
A clean public report is therefore not a review of every cookie in your application. Inspect your own authenticated session in browser developer tools and compare the attributes there. Keep real session values out of tickets, screenshots and shared debugging messages.
Keep reading
Related guides
HTTP security headers: what to check first
Understand CSP, HSTS and framing protection, then work through security header findings without breaking your website.
Read guide CachingCache-Control explained: no-cache, no-store and private
Choose a cache policy for public assets and personal pages, and understand why no-cache still allows storage.
Read guide