django-planet
Posts
Blogs
Authors
Search
Posts
Blogs
Feeds
Authors
Home
Blogs
Josh Karamuth
Why CSRF token cookies don't need to be httpOnly
July 20, 2024
Why CSRF token cookies don't need to be httpOnly
in blog
Josh Karamuth
original entry
Why CSRF token cookies don't need to be httpOnly
CSRF token cookies are typically sent without httpOnly set to true. But is that a secure practice?
Recent Posts
Honored to Become a Member of the Django Software Foundation
Weeknotes (2025 week 05)
An Introduction to Django Views
Django 5.2 simple_block_tag with HTMX
Code of Conduct++
Django News - Django 5.2 alpha 1 release - Jan 24th 2025
Djangonaut Space - New session 2025
Django earns the CHAOSS DEI Bronze badge 🫶
VS Code Extensions
Tips