Hacker News new | ask | show | jobs
by mjpuser 3063 days ago
I agree. The only reason I can think to justify this is that the author is implying you only should use the HttpOnly flag for security reasons. Still seems odd that they don’t know you can set cookies with JS.