Which browsers do support HttpOnly cookies?

穿精又带淫゛_ 提交于 2019-11-28 19:45:39

问题


Which browsers do support HttpOnly cookies, and since which version?

Please see http://www.codinghorror.com/blog/archives/001167.html for a discussion of HttpOnly cookies and XSS-prevention.


回答1:


Feel free to add to this list:

  • Internet Explorer since 6 sp1 (source, source)
  • Firefox since 2.0.0.5 (source)
  • Opera since 9.5 (possibly earlier) (source)
  • Safari since 4 (source)
  • Chrome since 1.0.154 (source)



回答2:


Up to date results can be found here:

http://www.browserscope.org/?category=security

(linked from the OWASP article mentioned above)




回答3:


OWASP have this documented. See http://www.owasp.org/index.php/HttpOnly




回答4:


All major browsers support HttpOnly.

  • Microsoft IE 5.0+
  • Mozilla Firefox 1.0+
  • Google Chrome
  • Apple Safari
  • Opera 8.0+


来源:https://stackoverflow.com/questions/528405/which-browsers-do-support-httponly-cookies

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!