July 20, 2024

Why CSRF token cookies don't need to be httpOnly

CSRF token cookies are typically sent without httpOnly set to true. But is that a secure practice?