I want to know the difference between an HttpOnly cookie and a Signed cookie.
Note: I am not talking about cookie with a secure flag.
As far as I know, HttpOnly tells the browser that cookie is only accessible by server. And Signed cookie is sent with a signature and detects if cookie is modified or not.
If using HttpOnly ensures that cookie is readOnly and can't be accessed by a script then why should I make that cookie signed?
And also if one of them is required then which one is better?