Which browsers do support HttpOnly cookies, and since which version?
Please see http://www.codinghorror.com/blog/archives/001167.html for a discussion of HttpOnly cookies and XSS-prevention.
Which browsers do support HttpOnly cookies, and since which version?
Please see http://www.codinghorror.com/blog/archives/001167.html for a discussion of HttpOnly cookies and XSS-prevention.
All major browsers support HttpOnly.
Feel free to add to this list:
Safari and Chrome may not have support yet--but it should be coming soon if it's not there already. Please edit this answer if you find a more recent reference!
OWASP have this documented. See http://www.owasp.org/index.php/HttpOnly