Cookie Security Attributes
Attributes set on HTTP cookies, chiefly Secure, HttpOnly and SameSite, that control when browsers send cookies and whether scripts can read them, protecting session cookies from theft and misuse.
The Secure attribute tells the browser to send a cookie only over HTTPS, preventing exposure on unencrypted connections. HttpOnly prevents client-side scripts from reading the cookie, limiting the damage from cross-site scripting. SameSite controls whether a cookie is sent with cross-site requests: Strict never sends it cross-site, Lax sends it on top-level navigations that use safe methods such as GET, and None sends it in all contexts but requires Secure. Domain, Path and expiry attributes further limit scope and lifetime.
Session cookies are effectively bearer credentials, so these attributes are standard requirements for web application security and are routinely checked in scans and penetration tests. Special cookie name prefixes let a site require that a cookie was set with the Secure attribute from an HTTPS page and, for the stricter host prefix, that it is bound to the exact host. Chromium-based browsers treat cookies without a SameSite attribute as Lax by default.
These attributes reduce risk but do not replace secure session management: session identifiers must be long and random, regenerated after login, invalidated at logout and expired after inactivity. Browser restrictions on third-party cookies continue to change, so cross-site integrations should be tested across browsers. Privacy laws such as GDPR and the EU ePrivacy rules separately govern consent for non-essential cookies.
Key points
- Secure restricts a cookie to HTTPS connections.
- HttpOnly hides a cookie from client-side scripts.
- SameSite limits cross-site sending and helps prevent CSRF.
- Cookie name prefixes can enforce secure, host-only cookies.
Where AiVibe comes in
AiVedha.ai's automated website security audit covers cookies among more than 170 checks, with severity ratings and remediation steps in its report.
Related terms
- Cross-Site Scripting (XSS)Cybersecurity & Compliance
- Cross-Site Request Forgery (CSRF)Cybersecurity & Compliance
- HTTP Security HeadersCybersecurity & Compliance
- Transport Layer Security (TLS)Cybersecurity & Compliance
- General Data Protection Regulation (GDPR)Cybersecurity & Compliance