Posts

Showing posts with the label Httponly

Check If Httponly Cookie Exists In Javascript

Answer : You can indirectly check to see if it exists by trying to set it to a value with javascript if it can't be set, then the HTTP Only Cookie must be there (or the user is blocking cookies). function doesHttpOnlyCookieExist(cookiename) { var d = new Date(); d.setTime(d.getTime() + (1000)); var expires = "expires=" + d.toUTCString(); document.cookie = cookiename + "=new_value;path=/;" + expires; if (document.cookie.indexOf(cookiename + '=') == -1) { return true; } else { return false; } } No. And see Rob's comments below. See this, which you probably already saw - http://en.wikipedia.org/wiki/HTTP_cookie#Secure_and_HttpOnly An HttpOnly cookie is not accessible via non-HTTP methods, such as calls via JavaScript (e.g., referencing "document.cookie")... Edit: Removed undefined response, I wrote a script that you may not be using :) I had the same problem. I solved it with the server setting anoth...