Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Set Secure, HttpOnly and SameSite Flags on Your Own App's Session Cookie and Check Them in DevTools

Beginner30 minPython 3 and Flask · Chrome, Edge or Firefox DevTools · curl · Sample file cookie_app.py

Course: Cyber Security · Chapter 41: Session Hijacking – Tokens, Cookies and Defence

Chapter 41 explains session hijacking; this lab adds the three cookie flags that make stolen or misused session cookies much harder.

Download cookie_app.py (training app, 30 lines)

Suppose we are a web developer at MakeMyTrip. A security review (like Lab 21) reported: "Session cookie is readable by JavaScript and has no Secure or SameSite flag." If a single XSS bug appears anywhere, an attacker's script could read that cookie and take over the user's session. We fix the cookie on a tiny training app first, so we know exactly what to change in the real code.

By the end you will be able to:

  • See a cookie's flags in DevTools and with curl -i.
  • Add HttpOnly, Secure and SameSite=Lax to a session cookie in code.
  • Prove the fix: document.cookie no longer shows the session.
  • Python 3 with Flask (Lab 29 step 1) and a browser. About 30 minutes.

Download cookie_app.py

Safety and ethics

Inspect and change cookies only in your own app on localhost. Copying someone else's session cookie, or using a cookie you found, to access their account is unauthorised access.

  1. Start the app in the folder where you saved it: python cookie_app.py (Mac/Linux: python3 cookie_app.py).

    What you should see: Running on http://127.0.0.1:5001.

  2. Look at the raw response header in a second terminal:

    curl -si http://localhost:5001/login | grep -i set-cookie
    

    What you should see: Set-Cookie: session_id=...; Path=/ with no HttpOnly, Secure or SameSite, and theme=dark; Path=/; SameSite=Lax.

  3. In the browser open http://localhost:5001/login (use localhost, not your IP). Press F12 → Application (Firefox: Storage) → Cookies → http://localhost:5001.

    What you should see: session_id with the HttpOnly and Secure columns empty and SameSite empty.

  4. Open the Console tab and type document.cookie → Enter. The session ID is printed: any script on the page can read it.

  5. Stop the app (Ctrl + C). Open cookie_app.py and change the line under # TODO (lab):

    resp.set_cookie("session_id", sid, httponly=True, secure=True, samesite="Lax")
    
  6. Start the app again and repeat step 2.

    What you should see: Set-Cookie: session_id=...; Secure; HttpOnly; Path=/; SameSite=Lax.

  7. In the browser, delete the old cookies (Application → Cookies → right-click → Clear), open /login again and look at the table.

    What you should see: session_id with ✓ in HttpOnly and Secure, and SameSite = Lax. Modern browsers accept Secure cookies on localhost; on a real site Secure works only over HTTPS.

  8. Run document.cookie in the Console again: only theme=dark appears. The session is hidden from JavaScript.

  9. Click Go to profile: it still says User: student01. The flags protect the cookie without breaking the login.
Mistake What happens Fix
Testing on http://​192.​168.​x.​x with Secure set The browser refuses the Secure cookie and login "breaks" Use localhost locally; HTTPS on real servers
Setting the flags in JavaScript document.cookie cannot set HttpOnly Set cookies on the server
Old cookie still in the browser You still see the unflagged cookie Clear cookies, then log in again
SameSite=None without Secure Browsers reject the cookie Use Lax, or None only with Secure for real cross-site needs
Putting secrets in non-session cookies Readable by scripts Keep secrets server-side; cookies hold only an ID

0 of 5 done

Check the cookies of a website you log in to every day (your own account). Which cookie looks like the session, and which flags does it have?

Check your answer

Open DevTools → Application → Cookies for that site. Session cookies usually have long random values and names like session, sid or __Host-.... On well-run sites they show ✓ HttpOnly, ✓ Secure and SameSite Lax or Strict. Only look; never copy or share your cookie values, because they work like a password.

Samjla ka? HttpOnly hides it from scripts, Secure keeps it on HTTPS, SameSite stops cross-site sending. Aata pudhe jaauya: Chapter 42 writes our own detection rule.