HTTP Security Headers

Set-Cookie — security attributes

Stores cookies in the browser — and its Secure, HttpOnly and SameSite attributes are what stand between a session cookie and theft or CSRF.

What it is

Set-Cookie writes a cookie to the browser. Cookies frequently carry session identifiers, so the header's attributes are security-critical: they control whether the cookie is sent over HTTP, whether JavaScript can read it, and whether it accompanies cross-site requests.

Security attributes

Secure
The cookie is only sent over HTTPS, never plain HTTP.
HttpOnly
JavaScript cannot read the cookie (document.cookie), blocking theft via XSS.
SameSite=Strict
Cookie is withheld on all cross-site requests — strongest CSRF protection.
SameSite=Lax
Sent on top-level cross-site navigations (GET) but not cross-site subrequests. The modern default.
SameSite=None
Sent on all cross-site requests. Requires Secure. Needed for legitimate third-party cookies.
Path / Domain
Scope the cookie to a path/domain. Prefer the narrowest scope.
__Host- prefix
Enforces Secure, Path=/ and no Domain — the safest cookie configuration.
HTTP RESPONSE HEADER
Set-Cookie: __Host-session=abc123; Max-Age=3600; Path=/; Secure; HttpOnly; SameSite=Lax

Why it matters

  • HttpOnly prevents a successful XSS from reading the session cookie, sharply limiting the damage of script injection.
  • Secure stops a session cookie from ever traveling over plain HTTP where it could be sniffed.
  • SameSite is a first-class defense against cross-site request forgery (CSRF), often removing the need for a separate CSRF token on GET flows.

Common mistakes

  • Omitting HttpOnly on a session cookie, so any XSS can immediately exfiltrate it.
  • Using SameSite=None without Secure, which modern browsers reject — the cookie is silently dropped.
  • Scoping a cookie to Domain=.example.com when a host-only cookie would do, widening exposure across subdomains.
  • Not using the __Host- prefix for sensitive cookies where it would enforce the safest defaults automatically.

How WebInspect checks this

  • WebInspect inspects each Set-Cookie and reports which of Secure, HttpOnly and SameSite are present.
  • It flags session-like cookies missing HttpOnly or Secure, and SameSite=None cookies that lack Secure.
  • It recognizes the __Host-/__Secure- prefixes and credits their hardened configuration.