Verifiedapp Blog
Home All posts

Tag

#cookies

Cookies

HttpOnly cookies: keeping session tokens away from XSS

If an attacker can run script on your page, the first thing they reach for is your session cookie. One cookie flag — HttpOnly — takes that prize off the table.

Jul 13, 2026 · 3 min read
Cookies

Cookie security in 5 minutes: Secure, HttpOnly, SameSite

A session cookie is the key to a logged-in account. Three small flags decide whether that key is protected or up for grabs. Here is the five-minute version.

May 11, 2026 · 2 min read
© VerifiedApp — automated security scanning & trust badges. RSS