I have tried to set a cookie using document.cookie = "tagname = test; secure"
but this does not set the secure flag. Am I setting it wrong? Can you only set it from a server response? I am also wondering that, because I have had a difficult time finding an example of its use, that it probably is not commonly used?
Thanks a bunch!
TL:DR
You have to use HTTPS to set a secure attribute
The normal (or formal, maybe) name is attribute. Since the flag refers to other things.
More Info
Cookie attributes:
More details and practical usages. Check Testing_for_cookies_attributes_(OTG-SESS-002)
UPDATES The following contents expire in June 2, 2016.
Cookie FlagsCookie flags are prefixes. At the moment, they are described in the RFC draft as a update to the RFC6265
These flags are used with the 'secure' attribute.
A cookie with this flag
because the flag is called
secure
, not security: