Cookies
Cookie flags
Secure, HttpOnly, SameSite.
What it is
Attributes on Set-Cookie that decide whether a cookie is sent over HTTPS only (Secure), hidden from JavaScript (HttpOnly), and sent on cross-site requests (SameSite).
Why it matters
They protect session cookies from theft via XSS and from being used in CSRF attacks.
Risk without it
A session cookie without HttpOnly can be stolen by any XSS; without Secure it can leak over HTTP; without SameSite it can be replayed cross-site.
Recommended
Secure; HttpOnly; SameSite=Lax (or Strict). Use the __Host- prefix for session cookies.