标签: cookies
我使用的是Chrome扩展名EditThisCookie,它可以显示Cookie是否为hostonly/httponly/secure:
hostonly/httponly/secure
我看到某些站点只有HostOnly,但没有HttpOnly,
HostOnly
HttpOnly
我知道设置cookie HttpOnly或Secure会阻止XSS获取cookie,
Secure
我的问题是,
HostOnly cookie可以阻止XSS获取cookie吗?