Cookies without HttpOnly

Cookies without HttpOnly in C#

Description

Browser scripts can read cookies that do not have the HttpOnly attribute.

Potential impact

  • XSS can expose session or authentication cookies to an attacker.

Remediation

Set CookieOptions.HttpOnly = true on cookies that client-side scripts do not need to read.

Examples

Before

csharp
response.Cookies.Append("sid", value);

After

csharp
response.Cookies.Append("sid", value, new CookieOptions { HttpOnly = true });

Explanation:

  • Before: An attacker exploiting XSS can read a cookie without HttpOnly through client-side scripts.
  • After: Enable CookieOptions.HttpOnly for cookies that do not require JavaScript access.

References