Does a CSRF cookie need to be HttpOnly? – security.stackexchange.com

We've recently were handed a security report containing the: Cookie(s) without HttpOnly flag set vulnerability, which we apparently had in one of our internal applications. The applied fix was as ...

from Hot Questions - Stack Exchange OnStackOverflow
via Blogspot

Share this

Artikel Terkait

0 Comment to "Does a CSRF cookie need to be HttpOnly? – security.stackexchange.com"