Need help with HTTPOnly attribute...

Posted on 2010-01-07
Medium Priority
Last Modified: 2012-05-08

I have code in the onSessionStart event that prevents JavaScript from accessing the session cookies thru the use of "HTTPOnly" attribute in the <cfheader> tag, and everything's working.  But once I started adding code that ends the session when the user closes the browser (see code below), the code that prevents JavaScript from accessing the session cookies NO longer works.

Can someone please tell me how can I resolve this?

Many thanks in advance.

<cffunction name="onSessionStart" output="false" returntype="void">
		<!--- Code that ends the session when user closes browser --->
		<cfcookie name="CFID" value="#session.CFID#" />
		<cfcookie name="CFTOKEN" value="#session.CFTOKEN#" />
                  <!--- HTTPOnly is a flag that tells the
browser to only submit the cookie via HTTP requests, which means it cannot be access via JavaScript --->
		<cfheader name="Set-Cookie" value="CFID=#session.CFID#;HTTPOnly">
		<cfheader name="Set-Cookie" value="CFTOKEN=#session.CFTOKEN#;HTTPOnly">

       <cfreturn />

Open in new window

Question by:WebAppDeveloper
1 Comment
LVL 25

Accepted Solution

dgrafx earned 2000 total points
ID: 26359999
you cannot, i don't believe, end a session when browser is closed
many before you have asked this question ...


Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The technique is by far very Simple! How we can export the ColdFusion query results to DOC file?  Well before writing this I researched a lot in Internet but did not found a good Answer anyways!  So i thought now i should share my small snippet w…
Hi. There are several upload tutorials using jquery and coldfusion. I found a very interesting one here Upload Your Files using Jquery & ColdFusion and Preview them (http://www.randhawaworld.com/) . I did keep the main js functions but made sever…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
Suggested Courses
Course of the Month15 days, 21 hours left to enroll

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question