Moderate Browser Question 127 of 229

What is the difference between cookies set from JavaScript versus HttpOnly?

Frontend Master · Speak this in 60–90 seconds · Faridabad & Delhi NCR

PICTURE THIS: A SENTENCE BECOMES TOKENS

The model does not read letters like humans. It reads these pieces, then predicts the next one.

Simple meaning

Document.cookie can set cookies the page can also read, so XSS can steal them.

1

WHY — Browser instead of guessing?

Why interviewers care about Browser:

They want a clean

contrast on Browser, not two memorised paragraphs.

Say what changes for

the developer, then one case where picking wrong hurts.

Stay structured

Name the idea, why it exists, then one short example.

Close cleanly

End with when you use it and one common pitfall.

2

STEPS — What happens with tokens?

Before the model can read a sentence, it goes through these steps:

  1. 1
    Document.cookie can set cookies

    the page can also read, so XSS can steal them.

  2. 2
    HttpOnly cookies are set

    by Set-Cookie from the server and are invisible to JS.

  3. 3
    Embeddings

    Session cookies should be HttpOnly

  4. 4
    CSRF tokens in a

    double-submit pattern are sometimes readable on purpose.

  5. 5
    Next token

    The model scores what should come next.

  6. 6
    Decode

    IDs turn back into readable text.

3

EXAMPLE — See it in action

Let's see how a real sentence is tokenized (tokens may vary by model):

Input text
“HttpOnly cookies are set by Set-Cookie from the server and are invisible to JS.”
Tokenized output
HttpOnlycookiesaresetbySet
Token IDs (example)
2987408337471632900

Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).

Key takeaway

Document.cookie can set cookies the page can also read, so XSS can steal them. HttpOnly cookies are set by Set-Cookie from the server and are invisible to JS.

Chat with us