Hacker News new | ask | show | jobs
by keeperofdakeys 4566 days ago
You have two cookies, one for HTTP, one for HTTPS. The latter uses a secure flag so it can't be seen with HTTP connections. When the user logs in, both are set.