Which cookie attribute prevents JavaScript from reading a session token?
- A httpOnly
- B secure
- C sameSite
- D path
Answer
httpOnly
secure restricts the cookie to HTTPS and sameSite defends against CSRF. Together they make cookies safer than localStorage for session tokens.





