KoderSolution Logo
HomeArticlesTutorialsForumAI LabRun Code
KoderSolution Logo

The world’s most advanced technical ecosystem for modern software engineers. Learn, build, and grow with next-generation developer tools and resources.

Engineering Newsletter

Join 100,000+ engineers receiving curated high-signal content weekly.

Platforms

  • Technical Articles
  • Interactive Tutorials
  • AI Coding Lab
  • Developer Forum
  • Developer Tools

Pages

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Disclaimer
  • Advertisement

Popular Topics

  • PHP
  • Laravel
  • Python
  • React.Js
  • MySQL
© 2026 KoderSolutionAll Rights Reserved
Developed Bymaksudur.dev
⚡

JavaScript

Topic Hub & Articles

JS Introduction

10 min

JS Where To

10 min

JS Output

10 min

Recap Quiz

5 Questions

JS Statements

10 min

JS Syntax

10 min

JS Comments

10 min

Recap Quiz

5 Questions

JS Variables

10 min

JS Let

10 min

JS Const

10 min

Recap Quiz

5 Questions

JS Operators

10 min

JS Arithmetic

10 min

JS Assignment

10 min

Recap Quiz

5 Questions

JS Data Types

10 min

JS Functions

10 min

JS Objects

10 min

Recap Quiz

5 Questions

JS Events

10 min

JS Strings

10 min

JS String Methods

10 min

Recap Quiz

5 Questions

JS String Search

10 min

JS String Templates

10 min

JS Numbers

10 min

Recap Quiz

5 Questions

JS Number Methods

10 min

JS BigInt

10 min

JS Arrays

10 min

Recap Quiz

5 Questions

JS Array Methods

10 min

JS Array Search

10 min

JS Array Sort

10 min

Recap Quiz

5 Questions

JS Array Iteration

10 min

JS Array Const

10 min

JS Dates

10 min

Recap Quiz

5 Questions

JS Date Formats

10 min

JS Date Get Methods

10 min

JS Date Set Methods

10 min

Recap Quiz

5 Questions

JS Math

10 min

JS Random

10 min

JS Booleans

10 min

Recap Quiz

5 Questions

JS Comparisons

10 min

JS If Else

10 min

JS Switch

10 min

Recap Quiz

5 Questions

JS Loop For

10 min

JS Loop For In

10 min

JS Loop For Of

10 min

Recap Quiz

5 Questions

JS Loop While

10 min

JS Break

10 min

JS Iterables

10 min

Recap Quiz

5 Questions

JS Sets

10 min

JS Maps

10 min

JS TypeOf

10 min

Recap Quiz

5 Questions

JS Type Conversion

10 min

JS Destructuring

10 min

JS Bitwise

10 min

Recap Quiz

5 Questions

JS RegExp

10 min

JS Errors

10 min

JS Scope

10 min

Recap Quiz

5 Questions

JS Hoisting

10 min

JS Strict Mode

10 min

JS This Keyword

10 min

Recap Quiz

5 Questions

JS Arrow Function

10 min

JS Classes

10 min

JS Modules

10 min

Recap Quiz

5 Questions

JS JSON

10 min

JS Debugging

10 min

JS Best Practices

10 min

Recap Quiz

5 Questions

JS Common Mistakes

10 min

JS Performance

10 min

JS Reserved Words

10 min

Recap Quiz

5 Questions

DOM Intro

10 min

DOM Methods

10 min

DOM Document

10 min

Recap Quiz

5 Questions

DOM Elements

10 min

DOM HTML

10 min

DOM Forms

10 min

Recap Quiz

5 Questions

DOM CSS

10 min

DOM Animation

10 min

DOM Events

10 min

Recap Quiz

5 Questions

DOM Event Listener

10 min

DOM Navigation

10 min

DOM Nodes

10 min

Recap Quiz

5 Questions

DOM Collections

10 min

DOM Node List

10 min

JS Window

10 min

JS Screen

10 min

JS Location

10 min

Recap Quiz

5 Questions

JS History

10 min

JS Navigator

10 min

JS Popup Alert

10 min

Recap Quiz

5 Questions

JS Timing

10 min

JS Cookies

10 min

JS Callbacks

10 min

JS Asynchronous

10 min

JS Promises

10 min

Recap Quiz

5 Questions

JS Async/Await

10 min

Progress
0%

0 / 92 Lessons

JavaScriptJS BOM
Lesson

JS Cookies

10 min reading
Free Course

JavaScript Cookies: document.cookie, Expiration, & Security Flags

Browser cookies are small data snippets stored by the web browser on behalf of websites. JavaScript can read and write client-side cookies via document.cookie.

Cookie Security Flags Architecture

flowchart TD
    CookieDecl["Set-Cookie Header / document.cookie"] --> Flags["Security Attributes"]
    Flags --> Secure["Secure: Transmit over HTTPS ONLY"]
    Flags --> HttpOnly["HttpOnly: Prevent JS access (Protects from XSS)"]
    Flags --> SameSite["SameSite=Strict/Lax: Protects from CSRF attacks"]
    Flags --> Exp["Expires / Max-Age: Controls persistence duration"]

Cookie Attributes Reference

Attribute Syntax Example Purpose
max-age max-age=3600 Expiration duration in seconds (3600 = 1 hour).
expires expires=UTC_STRING Absolute expiration date string.
path path=/ Specifies paths where cookie is accessible.
SameSite SameSite=Lax CSRF defense (Strict, Lax, or None).
Secure Secure Enforces transmission over HTTPS only.

Practical Code Example

// Demonstrating Cookie helper functions for setting, reading, and deleting cookies

// 1. Helper: Set Cookie with Expiration and Security Flags
function setCookie(name, value, days) {
  let expires = "";
  if (days) {
    const date = new Date();
    date.setTime(date.getTime() + (days * 24 * 60 * 60 * 1000));
    expires = `; expires=${date.toUTCString()}`;
  }
  // Setting cookie string with Path and SameSite flags
  document.cookie = `${encodeURIComponent(name)}=${encodeURIComponent(value)}${expires}; path=/; SameSite=Lax`;
}

// 2. Helper: Get Cookie Value by Name
function getCookie(name) {
  const nameEQ = encodeURIComponent(name) + "=";
  const cookieArray = document.cookie.split(";");

  for (let c of cookieArray) {
    c = c.trim();
    if (c.indexOf(nameEQ) === 0) {
      return decodeURIComponent(c.substring(nameEQ.length));
    }
  }
  return null;
}

// 3. Helper: Delete Cookie
function deleteCookie(name) {
  // Setting max-age=0 immediately expires the cookie!
  document.cookie = `${encodeURIComponent(name)}=; max-age=0; path=/`;
}

// Execution Demo
setCookie("theme_preference", "dark", 7);
console.log(`Read Cookie 'theme_preference': ${getCookie("theme_preference")}`);

Best Practices & Gotchas

  • Use HttpOnly for Authentication Tokens: Sensitive auth tokens (JWTs, session IDs) should be set by the server using HttpOnly headers so JavaScript cannot read them, preventing XSS token theft.
  • Always URL Encode Cookie Names & Values: Use encodeURIComponent() and decodeURIComponent() to handle special characters safely.
  • Deleting Cookies Requires Matching Path: To delete a cookie, set its max-age=0 (or past expiration date) using the exact same path attribute under which it was originally created.

Self-Check Challenge

Why should sensitive authentication session cookies be set with the HttpOnly flag from the backend server?

Save Your Progress

Unlock Your
Full Potential.

Sign in to track your learning journey, earn industry-recognized certificates, and join our elite developer community.

Quick Access With

Enterprise-Grade Security Protocol

Recommended Courses & Books

Try it Yourself

Experiment with the code from this lesson in our interactive playground.

Open Playground

Stuck on this lesson?

Join our community of senior developers.

Ask in Forum