From XHR, I had one "Set-Cookie: .ASPXAUTH". It was really installed, as I saw that next XHR, had this cookie inside in request part. The strange is why document.cookie doesnot contain it?
A:
HttpOnly is the answer, looks like in this area we have an old war.
dynback.com
2010-01-04 12:52:47
This is a security feature to protect cookie data against attacks like XSS.
Gumbo
2010-01-04 13:02:29