What is the difference between cookies set from JavaScript versus HttpOnly?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Document.cookie can set cookies the page can also read, so XSS can steal them.
WHY — Browser instead of guessing?
Why interviewers care about Browser:
contrast on Browser, not two memorised paragraphs.
the developer, then one case where picking wrong hurts.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Document.cookie can set cookies
the page can also read, so XSS can steal them.
- 2HttpOnly cookies are set
by Set-Cookie from the server and are invisible to JS.
- 3Embeddings
Session cookies should be HttpOnly
- 4CSRF tokens in a
double-submit pattern are sometimes readable on purpose.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
Document.cookie can set cookies the page can also read, so XSS can steal them. HttpOnly cookies are set by Set-Cookie from the server and are invisible to JS.