Contents

Security › Authentication & Authorization · also in HTTP, How Browsers Work

Cookie

A small piece of data the server asks the browser to store and send back automatically on later requests.

The server sets a cookie with a response header:

Set-Cookie: session_id=k3j2...9x; HttpOnly; Secure; SameSite=Lax; Path=/; Max-Age=86400

From then on the browser attaches it to every matching request:

Cookie: session_id=k3j2...9x

That automatic sending is what makes sessions work, and also what makes CSRF possible.

Attributes that matter for auth

AttributeWhat it doesUse it?
HttpOnlyJavaScript can’t read the cookie, so an XSS bug can’t steal itAlways, for auth cookies
SecureOnly sent over HTTPSAlways in production
SameSiteLimits sending on cross-site requests (details)Lax is a good default
Max-Age / ExpiresWhen it expires; without it, it’s deleted when the browser closesSet deliberately
Domain / PathWhich URLs receive itKeep as narrow as possible

A login cookie without HttpOnly and Secure is one of the most common findings in security reviews.