• NotSteve_@piefed.ca
    link
    fedilink
    English
    arrow-up
    11
    ·
    4 days ago

    I know enough about them (mainly a BE dev though) but I’m also a bit confused. A session token would be how you keep someone logged in, what’s wrong with that?

    • Elvith Ma'for@feddit.org
      link
      fedilink
      arrow-up
      9
      ·
      4 days ago

      What immediate stands out to me: the secure attribute is not set (only transmit via TLS, never unencrypted). Also - especially if used for a session cookie - the HttpOnly attribute should probably also be set (=value not accessible from JS, only sent in request headers).

      • NotSteve_@piefed.ca
        link
        fedilink
        English
        arrow-up
        5
        ·
        4 days ago

        Oh right, that makes sense; it’s been quite a while since I’ve done web development. That seems rather subtle though, right? Not sure if the comic OP is just flat anti-cookie without nuance but it gives that vibes

    • PoolloverNathan@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      4 days ago

      A session token… set by JavaScript, with no secure attribute, and no domain. (and no expiry, but I think that just uses browser lifetime)