• NotSteve_@piefed.ca
      link
      fedilink
      English
      arrow-up
      11
      ·
      3 days ago

      I know enough about them (mainly a BE dev though) but I’m also a bit confused. A session token would be how you keep someone logged in, what’s wrong with that?

      • Elvith Ma'for@feddit.org
        link
        fedilink
        arrow-up
        9
        ·
        3 days ago

        What immediate stands out to me: the secure attribute is not set (only transmit via TLS, never unencrypted). Also - especially if used for a session cookie - the HttpOnly attribute should probably also be set (=value not accessible from JS, only sent in request headers).

        • NotSteve_@piefed.ca
          link
          fedilink
          English
          arrow-up
          5
          ·
          3 days ago

          Oh right, that makes sense; it’s been quite a while since I’ve done web development. That seems rather subtle though, right? Not sure if the comic OP is just flat anti-cookie without nuance but it gives that vibes

      • PoolloverNathan@programming.dev
        link
        fedilink
        arrow-up
        2
        ·
        3 days ago

        A session token… set by JavaScript, with no secure attribute, and no domain. (and no expiry, but I think that just uses browser lifetime)