Skip to content
Back to skills

Session Cookie Flags

ASecurity

Use when reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers.

  • 74,358 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
developmentjavascriptgojavafrontendsecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add thedaviddias/Front-End-Checklist --skill session-cookie-flags --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Session Cookie Flags?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Session Cookie Flags
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thedaviddias-session-cookie-flags/badge)](https://www.skillsdirectory.com/skills/thedaviddias-session-cookie-flags)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: session-cookie-flags
description: "Use when reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers."
metadata:
  category: security
  priority: high
  difficulty: beginner
  estimatedTime: "15"
  source: frontendchecklist.io
  url: https://frontendchecklist.io/rules/security/session-cookie-flags
---

# Set Secure, HttpOnly, and SameSite flags on session cookies

Missing cookie flags are one of the most common and easily fixed authentication weaknesses. Without Secure, session tokens are transmitted in plain text over HTTP and can be captured by network eavesdroppers. Without HttpOnly, any XSS payload can exfiltrate the session token in one line. Without SameSite, any website can trigger authenticated actions on behalf of the victim without their knowledge.

## Quick Reference

- Secure — cookie is only sent over HTTPS, never plain HTTP
- HttpOnly — cookie is invisible to JavaScript (blocks XSS theft)
- SameSite=Strict or Lax — prevents the cookie from being sent on cross-site requests (blocks CSRF)
- Never use SameSite=None without also setting Secure and understanding the CSRF implications

## Check

Check whether session and authentication cookies are set with the Secure, HttpOnly, and SameSite flags.

## Fix

Update the server's cookie configuration to include Secure, HttpOnly, and SameSite=Strict (or Lax) on all session and auth cookies.

## Explain

Explain what each cookie security flag does and the specific attack each one prevents.

## Code Review

Review all Set-Cookie headers and cookie creation code. Flag any cookies missing the HttpOnly flag, absent Secure flag, or an unspecified or overly permissive SameSite setting.

---

For full implementation details, code examples, and framework-specific guidance,
see `references/rule.md`.

Rule page: https://frontendchecklist.io/rules/security/session-cookie-flags

Files in this skill

  • SKILL.md1.9 KB
  • references/rule.md6.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…