django-planet
Posts
Blogs
Authors
Search
Posts
Blogs
Feeds
Authors
Home
Blogs
Josh Karamuth
Why CSRF token cookies don't need to be httpOnly
July 20, 2024
Why CSRF token cookies don't need to be httpOnly
in blog
Josh Karamuth
original entry
Why CSRF token cookies don't need to be httpOnly
CSRF token cookies are typically sent without httpOnly set to true. But is that a secure practice?
Recent Posts
PyCon Italia 2025
DjangoCon Europe 2025
Ungoogling my life
Happy International Women's Day! 🎉 💜
Break django-admin commands into subcommands
Redundant Linux backups with a single command
Notes from the Internet: How Dostoevsky’s Underground Man Lives Online
Django News - Django 5.1.7, 5.0.13, and 4.2.20 - Mar 7th 2025
Django security releases issued: 5.1.7, 5.0.13 and 4.2.20
Why I can't use a new tech-stack