Which browsers do support HttpOnly cookies, and since which version?
Please see http://www.codinghorror.com/blog/archives/001167.html for a discussion of HttpOnly cookies and XSS-prevention.
Michael Haren
Up to date results can be found here:
http://www.browserscope.org/?category=security
(linked from the OWASP article mentioned above)
OWASP have this documented. See http://www.owasp.org/index.php/HttpOnly
All major browsers support HttpOnly.
- Microsoft IE 5.0+
- Mozilla Firefox 1.0+
- Google Chrome
- Apple Safari
- Opera 8.0+
来源:https://stackoverflow.com/questions/528405/which-browsers-do-support-httponly-cookies