Was this page helpful?
Your feedback about this content is important. Let us know what you think.
Additional feedback?
1500 characters remaining
Export (0) Print
Expand All

HttpCookiesSection.HttpOnlyCookies Property

This API supports the .NET Framework infrastructure and is not intended to be used directly from your code.

Gets or sets a value indicating whether the support for the browser's HttpOnly cookie is enabled.

Namespace:  System.Web.Configuration
Assembly:  System.Web (in System.Web.dll)

<ConfigurationPropertyAttribute("httpOnlyCookies", DefaultValue := False)> _
Public Property HttpOnlyCookies As Boolean

Property Value

Type: System.Boolean
true if support for the HttpOnly cookie is enabled; otherwise, false. The default is false.

The httpCookies element supports the use of HttpOnly cookies. HttpOnly cookies (cookies with the HttpOnly attribute) were introduced in Internet Explorer 6 to help mitigate the risk of cross-site scripting. The HttpOnly attribute prevents cookies from being accessed through client-side script. Any information contained in an HttpOnly cookie is less likely to be disclosed to a hacker or a malicious Web site. For more information, search MSDN (msdn.microsoft.com) for "HttpOnly."

The following code example shows how to use the HttpOnlyCookies property.

            ' Get the current HttpOnlyCookies. 
            Dim httpOnlyCookiesValue As Boolean = _

            ' Set the HttpOnlyCookies.
            httpCookiesSection.HttpOnlyCookies = _

.NET Framework

Supported in: 4.6, 4.5, 4, 3.5, 3.0, 2.0
© 2015 Microsoft