Forum Discussion

draco's avatar
draco
Icon for Nimbostratus rankNimbostratus
Mar 11, 2020

Http only flag set on applications cookies

Hi All

 

If i set the http only attribute for the cookies learnt in the ASM policy, then when I access the web application, and inspect the same via browser, it should show that the cookie has http only attribute enabled??

1 Reply

  • P_K's avatar
    P_K
    Icon for Altostratus rankAltostratus

    That is correct! You are basically forcing browser to access cookies via http and https by enabling httponly attribute in ASM.