Secure cookie flags (HttpOnly, Secure, SameSite)
Në shqip: Atributet e sigurisë së cookie-ve
ShpjegimiSQ
Cookie-t e sesionit duhet të kenë tre atribute: HttpOnly (JavaScript-i s'mund t'i lexojë — mbron nga XSS), Secure (dërgohen vetëm me HTTPS) dhe SameSite (s'dërgohen nga faqe të tjera — mbron nga CSRF).
EnglishEN
Session cookies should have three flags: HttpOnly (JavaScript can't read them — protects against XSS), Secure (sent only over HTTPS) and SameSite (not sent from other sites — protects against CSRF).
Si ta mendosh
Si tri kyçe në të njëjtën derë, secila kundër një lloj hajduti.
Lexoje në anglisht
Like three locks on the same door, each against a different kind of burglar.
Shembull koditext
Set-Cookie: sesioni=abc123; HttpOnly; Secure; SameSite=Lax