Labs · Cyber Security
Lab: Set Secure, HttpOnly and SameSite Flags on Your Own App's Session Cookie and Check Them in DevTools
Course: Cyber Security · Chapter 41: Session Hijacking – Tokens, Cookies and Defence
Chapter 41 explains session hijacking; this lab adds the three cookie flags that make stolen or misused session cookies much harder.
Chala mitrano! After you log in, a website remembers you with a session cookie. Whoever has that cookie is "you". Three small flags protect it: HttpOnly (JavaScript cannot read it), Secure (only sent over HTTPS) and SameSite (not sent from other sites' requests). Today we add all three in one line and check them in DevTools. Chala!
चला मित्रांनो! तुम्ही login केल्यावर website तुम्हाला session cookie ने लक्षात ठेवते. ज्याच्याकडे ती cookie आहे तो "तुम्ही". तीन छोटे flags तिचं रक्षण करतात: HttpOnly (JavaScript वाचू शकत नाही), Secure (फक्त HTTPS वर पाठवली जाते) आणि SameSite (दुसऱ्या sites च्या requests मधून पाठवली जात नाही). आज आपण तिन्ही एका line मध्ये लावणार आणि DevTools मध्ये check करणार. चला!
चलो दोस्तों! Login के बाद website आपको session cookie से याद रखती है। जिसके पास वो cookie है वो "आप" हैं। तीन छोटे flags उसकी रक्षा करते हैं: HttpOnly (JavaScript पढ़ नहीं सकता), Secure (सिर्फ HTTPS पर भेजी जाती है) और SameSite (दूसरी sites की requests से नहीं भेजी जाती)। आज हम तीनों एक line में लगाएँगे और DevTools में check करेंगे। चलो!
Suppose we are…
Suppose we are a web developer at MakeMyTrip. A security review (like Lab 21) reported: "Session cookie is readable by JavaScript and has no Secure or SameSite flag." If a single XSS bug appears anywhere, an attacker's script could read that cookie and take over the user's session. We fix the cookie on a tiny training app first, so we know exactly what to change in the real code.
Goal of this lab
By the end you will be able to:
- See a cookie's flags in DevTools and with
curl -i. - Add
HttpOnly,SecureandSameSite=Laxto a session cookie in code. - Prove the fix:
document.cookieno longer shows the session.
What you need (all free)
- Python 3 with Flask (Lab 29 step 1) and a browser. About 30 minutes.
Safety and ethics
Inspect and change cookies only in your own app on localhost. Copying someone else's session cookie, or using a cookie you found, to access their account is unauthorised access.
Steps
-
Start the app in the folder where you saved it:
python cookie_app.py(Mac/Linux:python3 cookie_app.py).What you should see:
Running on http://127.0.0.1:5001. -
Look at the raw response header in a second terminal:
curl -si http://localhost:5001/login | grep -i set-cookieWhat you should see:
Set-Cookie: session_id=...; Path=/with no HttpOnly, Secure or SameSite, andtheme=dark; Path=/; SameSite=Lax. -
In the browser open
http://localhost:5001/login(uselocalhost, not your IP). Press F12 → Application (Firefox: Storage) → Cookies →http://localhost:5001.What you should see:
session_idwith the HttpOnly and Secure columns empty and SameSite empty. -
Open the Console tab and type
document.cookie→ Enter. The session ID is printed: any script on the page can read it. -
Stop the app (Ctrl + C). Open
cookie_app.pyand change the line under# TODO (lab):resp.set_cookie("session_id", sid, httponly=True, secure=True, samesite="Lax") -
Start the app again and repeat step 2.
What you should see:
Set-Cookie: session_id=...; Secure; HttpOnly; Path=/; SameSite=Lax. -
In the browser, delete the old cookies (Application → Cookies → right-click → Clear), open
/loginagain and look at the table.What you should see:
session_idwith ✓ in HttpOnly and Secure, and SameSite =Lax. Modern browsers accept Secure cookies onlocalhost; on a real site Secure works only over HTTPS. -
Run
document.cookiein the Console again: onlytheme=darkappears. The session is hidden from JavaScript. - Click Go to profile: it still says
User: student01. The flags protect the cookie without breaking the login.
Ravindra Bagale's Tip
Most frameworks have one setting for this: Django SESSION_COOKIE_SECURE and SESSION_COOKIE_HTTPONLY, Express cookie: { httpOnly, secure, sameSite }, PHP session.cookie_httponly. Use Lax for most sites and Strict for banking-style apps. Ek line, motha fayda!
Ravindra Bagale's Tip – मराठी
बहुतेक frameworks मध्ये यासाठी एक setting असते: Django SESSION_COOKIE_SECURE आणि SESSION_COOKIE_HTTPONLY, Express cookie: { httpOnly, secure, sameSite }, PHP session.cookie_httponly. बहुतेक sites साठी Lax आणि banking सारख्या apps साठी Strict वापरा. एक line, मोठा फायदा!
Ravindra Bagale's Tip – हिंदी
ज़्यादातर frameworks में इसके लिए एक setting होती है: Django SESSION_COOKIE_SECURE और SESSION_COOKIE_HTTPONLY, Express cookie: { httpOnly, secure, sameSite }, PHP session.cookie_httponly। ज़्यादातर sites के लिए Lax और banking जैसे apps के लिए Strict इस्तेमाल करो। एक line, बड़ा फ़ायदा!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
Testing on http://192.168.x.x with Secure set |
The browser refuses the Secure cookie and login "breaks" | Use localhost locally; HTTPS on real servers |
| Setting the flags in JavaScript | document.cookie cannot set HttpOnly |
Set cookies on the server |
| Old cookie still in the browser | You still see the unflagged cookie | Clear cookies, then log in again |
SameSite=None without Secure |
Browsers reject the cookie | Use Lax, or None only with Secure for real cross-site needs |
| Putting secrets in non-session cookies | Readable by scripts | Keep secrets server-side; cookies hold only an ID |
Self-check checklist
0 of 5 done
Try-at-home challenge
Check the cookies of a website you log in to every day (your own account). Which cookie looks like the session, and which flags does it have?
Check your answer
Open DevTools → Application → Cookies for that site. Session cookies usually have long random values and names like session, sid or __Host-.... On well-run sites they show ✓ HttpOnly, ✓ Secure and SameSite Lax or Strict. Only look; never copy or share your cookie values, because they work like a password.
Samjla ka? HttpOnly hides it from scripts, Secure keeps it on HTTPS, SameSite stops cross-site sending. Aata pudhe jaauya: Chapter 42 writes our own detection rule.