Checks

Cookie security attributes look good

Every cookie on this response had the attributes this scan expects.

Why it matters

Secure, HttpOnly, and SameSite are the controls that keep a cookie off plaintext HTTP and out of document.cookie.

What to do

No change is required for the cookies observed on this response.

Reference

Cookie attributes such as Secure, HttpOnly, and SameSite protect session tokens in browsers.

OWASP Session Management Cheat Sheet