django-planet
Posts
Blogs
Authors
Search
Posts
Blogs
Feeds
Authors
Home
Blogs
Josh Karamuth
Why CSRF token cookies don't need to be httpOnly
July 20, 2024
Why CSRF token cookies don't need to be httpOnly
in blog
Josh Karamuth
original entry
Why CSRF token cookies don't need to be httpOnly
CSRF token cookies are typically sent without httpOnly set to true. But is that a secure practice?
Recent Posts
EuroPython 2025
Django News - New Django Fellow Position! - Jun 13th 2025
The currency of open-source
Django bugfix releases issued: 5.2.3, 5.1.11, and 4.2.23
Autogenerating og:images with Jekyll
Better Django management commands with django-click and django-typer
DSF calls for applicants for a Django Fellow
Django News - Django security releases issued: 5.2.2, 5.1.10, and 4.2.22 - Jun 6th 2025
Preserving referential integrity with JSON fields and Django
Django security releases issued: 5.2.2, 5.1.10, and 4.2.22