logoalt Hacker News

Sohcahtoa82yesterday at 10:14 PM0 repliesview on HN

HttpOnly makes it so XSS can't steal your token, but that won't stop XSS from using your token.