Comment on XSS vulnerability found in GithubparentComments−pilif15yI would assume that the session cookie is_github_seswhich is the only one that's set as both httponly and secure and, by the way, doesn't appear in document.cookie
Comments
I would assume that the session cookie is
_github_ses
which is the only one that's set as both httponly and secure and, by the way, doesn't appear in document.cookie