pocketbase-sveltekit-auth icon indicating copy to clipboard operation
pocketbase-sveltekit-auth copied to clipboard

httpOnly: false is it safe? use an api to get cookie server side instead?

Open robthepaper opened this issue 1 year ago • 0 comments

Hi @jianyuan , thanks for your project, I am using part of your code to implement with my project. Was wondering if it is safe to set httpOnly to false?

What do you think about setting an server side api to retrieve the cookie content instead of accessing it in js client side with document.cookie?

robthepaper avatar Jul 28 '24 12:07 robthepaper