django-planet
Posts
Blogs
Authors
Search
Posts
Blogs
Feeds
Authors
Home
Blogs
Josh Karamuth
Why CSRF token cookies don't need to be httpOnly
July 20, 2024
Why CSRF token cookies don't need to be httpOnly
in blog
Josh Karamuth
original entry
Why CSRF token cookies don't need to be httpOnly
CSRF token cookies are typically sent without httpOnly set to true. But is that a secure practice?
Recent Posts
DjangoCon US 2025
DSF member of the month - Jake Howard
Django News - Django and AI - Aug 1st 2025
Round up for July '25
Django: write a custom URL path converter to match given strings
Djangonaut Space is looking for contributors to be mentors
Django: split ModelAdmin.get_queryset() by view
Django News - DjangoCon US 2025 Talks Announced - Jul 25th 2025
DjangoCon Africa 2025 Heads to Arusha 🇹🇿
Deploying a Django App to Sevalla