Siguria

Secure cookie flags (HttpOnly, Secure, SameSite)

Në shqip: Atributet e sigurisë së cookie-ve

ShpjegimiSQ

Cookie-t e sesionit duhet të kenë tre atribute: HttpOnly (JavaScript-i s'mund t'i lexojë — mbron nga XSS), Secure (dërgohen vetëm me HTTPS) dhe SameSite (s'dërgohen nga faqe të tjera — mbron nga CSRF).

EnglishEN

Session cookies should have three flags: HttpOnly (JavaScript can't read them — protects against XSS), Secure (sent only over HTTPS) and SameSite (not sent from other sites — protects against CSRF).

Si ta mendosh

Si tri kyçe në të njëjtën derë, secila kundër një lloj hajduti.

Lexoje në anglisht

Like three locks on the same door, each against a different kind of burglar.

Shembull koditext

Set-Cookie: sesioni=abc123; HttpOnly; Secure; SameSite=Lax

Terma të lidhur