Cookie Attributes
Cookie attributes control how cookies behave: when they're sent, where they're accessible, and how long they last.
Domain Attribute
Purpose: Specifies which domains can access the cookie
Behavior:
- If set: Cookie is accessible by the specified domain and its subdomains
- If not set: Cookie is only accessible by the exact domain that set it
Examples:
Set-Cookie: user=john; Domain=example.com
This cookie is accessible by:
example.comwww.example.comshop.example.com- Any subdomain of
example.com
Important Notes:
- Cannot set
Domainto a top-level domain (e.g.,.com) - Setting
Domain=example.comis equivalent toDomain=.example.com(dot is optional) - Subdomains CAN access parent domain cookies, but parent CANNOT access subdomain-specific cookies
Testing: Use the Parent-Subdomain Test pages to experiment.
Path Attribute
Purpose: Restricts cookie to specific URL paths
Behavior:
- Cookie is only sent with requests to paths that match or are under the specified path
- Default is
/if not specified
Examples:
Set-Cookie: cart=items; Path=/shop
This cookie is sent with:
/shop/shop/cart/shop/products/item1- NOT with
/or/about
SameSite Attribute
Purpose: Controls when cookies are sent in cross-site requests
Values:
- Strict: Cookie is only sent with same-site requests (most restrictive)
- Lax: Cookie is sent with same-site requests and top-level navigations (default in modern browsers)
- None: Cookie is sent with all requests, including cross-site (requires
Secureflag)
Understanding Top-Level Navigation
Top-level navigation refers to navigation that changes the browser's main window/tab URL. This includes:
✅ Examples of Top-Level Navigation (SameSite=Lax cookies ARE sent):
- User clicks a link:
<a href="https://other-site.com/page">Click</a> - User submits a form:
<form method="GET" action="https://other-site.com/submit"> - User types URL in address bar and presses Enter
- User follows a redirect (301/302) to different domain
- User clicks browser back/forward buttons that navigate to different site
- Window/tab opened via
window.open()navigates to different domain
❌ Examples of NON-Top-Level Navigation (SameSite=Lax cookies are NOT sent):
- AJAX/Fetch request:
fetch('https://other-site.com/api') - Image load:
<img src="https://other-site.com/image.jpg"> - Iframe navigation:
<iframe src="https://other-site.com/page"></iframe> - CSS/JavaScript resource load:
<link href="https://other-site.com/style.css"> - Background request (e.g., pixel tracking):
<img src="https://tracker.com/pixel.gif">
Key Distinction: Top-level navigation changes the URL bar. Non-top-level requests are "sub-resource" requests that don't change the visible URL.
Examples:
Set-Cookie: session=abc; SameSite=Strict
Set-Cookie: tracking=xyz; SameSite=None; Secure
Impact on Third-Party Cookies:
SameSite=Noneis required for cross-site cookie sending- Modern browsers increasingly restrict
SameSite=Nonecookies
Secure Attribute
Purpose: Ensures cookie is only sent over HTTPS
Behavior:
- If present: Cookie only sent over secure (HTTPS) connections
- If absent: Cookie sent over both HTTP and HTTPS
Example:
Set-Cookie: session=abc; Secure
Note: Secure is required when SameSite=None
HttpOnly Attribute
Purpose: Prevents JavaScript access to the cookie
Behavior:
- If present: Cookie cannot be accessed via
document.cookiein JavaScript - If absent: Cookie can be read and modified via JavaScript
Example:
Set-Cookie: session=abc; HttpOnly
Security Benefit: Protects cookies from XSS (Cross-Site Scripting) attacks
Expires and Max-Age
Purpose: Control when the cookie expires
Expires:
- Sets an absolute expiration date
- Format:
Expires=Wed, 21 Oct 2025 07:28:00 GMT
Max-Age:
- Sets relative expiration time in seconds
- Format:
Max-Age=3600(1 hour)
Session Cookies:
- If neither is set, cookie expires when browser closes
Examples:
Set-Cookie: preference=dark; Expires=Wed, 21 Oct 2025 07:28:00 GMT
Set-Cookie: preference=dark; Max-Age=3600
Combining Attributes
Example:
Set-Cookie: session=abc123; Domain=example.com; Path=/; Secure; HttpOnly; SameSite=Strict; Max-Age=3600
This creates a cookie that:
- Is accessible by example.com and subdomains
- Is available for all paths
- Only sent over HTTPS
- Cannot be accessed by JavaScript
- Only sent with same-site requests
- Expires in 1 hour
Testing Attributes
Use the playground to test each attribute:
Observe HTTP request/response headers to see how attributes affect cookie behavior.
Next Steps
- Learn about First-Party vs Third-Party cookies
- Understand Cross-Domain Behavior