Is that really how httpOnly cookies work though? That and cross-origin is supposed to solve that, but I might not be aware of the work-around you're referring to. Did a search that turned up nothing, do you have a source?
I can't try myself right now. But last time I checked it's not at all that easy. What am I missing?
Comments
Is that really how httpOnly cookies work though? That and cross-origin is supposed to solve that, but I might not be aware of the work-around you're referring to. Did a search that turned up nothing, do you have a source?
I can't try myself right now. But last time I checked it's not at all that easy. What am I missing?
Well, no, but you wouldn't set httpOnly if you wanted to do that