django-planet
Posts
Blogs
Feeds
Authors
Posts
Blogs
Authors
Search
Home
Blogs
Josh Karamuth
Why CSRF token cookies don't need to be httpOnly
July 20, 2024
Why CSRF token cookies don't need to be httpOnly
in blog
Josh Karamuth
original entry
Why CSRF token cookies don't need to be httpOnly
CSRF token cookies are typically sent without httpOnly set to true. But is that a secure practice?
Recent Posts
Django is now a CVE Numbering Authority (CNA)
DSF member of the month - Anna Makarudze
The State of Django 2025
On the Air for Django’s 20th Birthday: Special Event Station W2D
Django News - Django 6.0 beta 1 released - Oct 24th 2025
Django, what the JOIN? with Simon Charette
Weeknotes (2025 week 43)
PyCharm & Django annual fundraiser
Django 6.0 beta 1 released
My favorite Django packages