mikewest / internetdrafts

4 stars 4 forks source link

`httponly` per default. #1

Open mikewest opened 9 years ago

mikewest commented 9 years ago

@annevk asked about httponly. We can probably set it by default for origin cookies. I'll look into that.

annevk commented 9 years ago

Note that at the moment we only expose cookies through document.cookie and that API is quite broken.