document.cookie is an empy string, even if some cookies are not httpOnly

Viewed 107

In php, I return cookie headers over https, but some cookies are NOT marked httpOnly. Yet, document.cookie contains an empty string in the browser when run over https (tested with chrome, firefox, edge).

As an example, I created the following PHP script:

<?php
setcookie("c1", "v1", 0, "/", false, false);
setcookie("c2", "v2", 0, "/", false, false);
header("Set-Cookie: c3=v3; expires=0;", false);
header("Set-Cookie: c4=v4; expires=0; SameSite=Strict; Secure", false);
?><!DOCTYPE html>
<html>
<head>
</head>
<body>
<div id="display_here"> </div>
<script type="text/javascript">
document.getElementById("display_here").textContent = '"' + document.cookie + '"';
</script>
</body>
</html>

The first two cookies are created with the standard setcookie() PHP function. The last two I create directly by setting the header, so I have more control over what is returned.

The javaScript line at the bottom shows document.cookie is empty. If I inspect the cookies in Chrome (with the dialog), they all exist. However, they are not available to the script. According to RFC 6265 they should be available.

Note that the problem only occurs when running over an https connection. When I use http, it works, but that pretty useless.

What is wrong here?

0 Answers
Related