Please note that, even if you would be able to set the cookie as httpOnly, the token is still available in JS because (you just read it off the query string ...
確定! 回上一頁