is there a way to set a httponly cookie with blazor server side? Setting a non httponly one with js-interop is not a problem but in case of httponly it is obviously not possible this way.
Thanks in advance Holger
is there a way to set a httponly cookie with blazor server side? Setting a non httponly one with js-interop is not a problem but in case of httponly it is obviously not possible this way.
Thanks in advance Holger
It seems that HttpOnly cookies are not accepted with Blazor Server as they are with Blazor WASM.
One of the reasons I was interested in using HttpOnly cookies with Blazor Server was for passing authentication tokens from a Blazor App to some back-end in a secure fashion.
Fortunately, there is a secure alternative to HttpOnly cookies in Blazor Server that may assist you. This is called ASP.NET Core Protected Browser Storage. You can store what ever you want in local storage or session storage, but it will be encrypted so that only the server can decrypt and read the stored details. This reduces the potential risk of tampering with stored data. While this is technically different to HttpOnly cookies, it can be used as a solution to solve similar problems.
You can read more about it here: ASP.NET Core Protected Browser Storage