HttpOnly Cookies Overview PRO

When the server side sends back to the client HTTP headers that instructs the client to create a new cookie (or update a cookie that already exists), the cookie on the client side can be accessed using code written in JavaScript.

HttpOnly cookies cannot be accessed using code written in JavaScript. In order to create a new cookie (or update a cookie that already exists), which is an HttpOnly cookie, the HTTP header that instructs the client to create (or update) a cookie should include the HttpOnly additional flag.

Set-Cookie: <name>=<value>[; <Max-Age>=<age>]
[; expires=<date>][; domain=<domain_name>]
[; path=<some_path>][; secure][; HttpOnly]

When developing our server side in PHP we can easily create an HttpOnly cookie. We just need to pass over the value true to the httponly parameter of the setcookie method.

bool setcookie (string $name 
		[, string $value
		[, int $expire = 0
		[, string $path
		[, string $domain
		[, bool $secure = false
		[, bool $httponly = false ]]]]]] )

The session cookie can be configured to be httponly through the php.ini file by referring the cookie_httponly property of the session and assigning it with true.

session.cookie_httponly = true;

We can alternatively call the session_set_cookie_params function and pass over true to the httponly parameter.

void session_set_cookie_params (int $lifetime 
				[, string $path
				[, string $domain
				[, bool $secure = false
				[, bool $httponly = false ]]]] )

 

Share:

The Visitor Design Pattern

The Visitor Design Pattern

The visitor design pattern allows us to add operations to objects that already exist without modifying their classes and without extending them.

What are Anti Patterns?

Anti Patterns

Unlike design patterns, anti patterns just seem to be a solution. However, they are not a solution and they cause additional costs.

Virtual Threads in Java Professional Seminar

Virtual Threads in Java

The use of virtual threads can assist us with improving the performance of our code. Learn how to use virtual threads effectively.

NoSQL Databases Courses, Seminars, Consulting, and Development

MongoDB Design Patterns Meetup

The use of MongoDB involves with various cases in which we can overcome performance issues by implementing specific design patterns.

image of woman and database

Record Classes in Java

Learn how to define record classes in Java, and when to use record classes in your code. Stay up to date with the new Java features.

Accessibility | Career | Conferences | Design Patterns | JavaScript | Meetups | PHP | Podcasts | Python | Self Learning

Teaching Methodologies | Fullstack | C++ | C# | CSS | Node.js | Angular | Java | Go | Android | Kotlin | Swift | Academy

Front End Development | Scala | Architectures | Cloud | Big Data | Internet of Things | Kids Learn Programming

The Beauty of Code

Coding is Art! Developing Code That Works is Simple. Develop Code with Style is a Challenge!

Skip to content Update cookies preferences