Is it possible to create a session cookie / httponly cookie via an API call ?
I am building an Authentication system using React and PHP.
From front end I am calling login API to validate the user id and password and if authenticated then I am generating a token , storing it in a database and returning this to the client :
{"user":"usr1","status":"AUTHENTICATED","token":"56etXss32124hWZ31AAf"}
And I am storing that in cookie so that my front-end knows that the user is logged in.
Now I do not want to store the token in normal cookie. The user and status is ok to store in normal cookie and I have to store at least the status, to keep my logged in state alive even after page refresh .
I want to store the token in a session cookie or httponly cookie to make the transaction more secure. And also I want to set this token to httponly cookie so that when I make another API call to modify any user specified data this token is passed to my server and I can validate the user.
Can anyone please suggest me how to achieve this ?