Reputation: 4566
From XHR, I had one "Set-Cookie: .ASPXAUTH". It was really installed, as I saw that next XHR, had this cookie inside in request part. The strange is why document.cookie doesnot contain it?
Upvotes: 1
Views: 468
Reputation: 4566
HttpOnly is the answer, looks like in this area we have an old war.
Upvotes: 1