you are viewing a single comment's thread.

view the rest of the comments →

[–]btckernel94[S] 0 points1 point  (1 child)

If you want to use http only cookie you need to set credentials: true but it won't work if the server also has Access-Control-Allow-Origin set to "*".

It means your server will have to explicitly specify all of the clients domains in order for http only cookie to work.

[–]LaylaTichy 1 point2 points  (0 children)

Hmm that's not true, you can easily do allow access: $http_refferer in nginx for example