Skip to content

Cookie Security #267

Answered by tillsanders
LokiDieKatze asked this question in Q&A
Discussion options

You must be logged in to vote

I believe there is no encryption baked into cookieconsent. That really depends on the cookies your application sets and wether it choses to encrypt them. Cookieconsent is only setting one cookie itself, which is the cc_cookie that contains the user settings. So I think you're looking in the wrong place. Or I misunderstood your question.

Regarding httpOnly – you cannot set those on the client. That is exactly what makes them (more) secure. More on that here: https://stackoverflow.com/questions/14691654/set-a-cookie-to-httponly-via-javascript

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by orestbida
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants