• Elvith Ma'for@feddit.org
    link
    fedilink
    arrow-up
    9
    ·
    4 days ago

    What immediate stands out to me: the secure attribute is not set (only transmit via TLS, never unencrypted). Also - especially if used for a session cookie - the HttpOnly attribute should probably also be set (=value not accessible from JS, only sent in request headers).

    • NotSteve_@piefed.ca
      link
      fedilink
      English
      arrow-up
      5
      ·
      4 days ago

      Oh right, that makes sense; it’s been quite a while since I’ve done web development. That seems rather subtle though, right? Not sure if the comic OP is just flat anti-cookie without nuance but it gives that vibes