Is it possible to create a session cookie / httponly cookie via an API call?

Viewed 24

Is it possible to create a session cookie / httponly cookie via an API call ?

I am building an Authentication system using React and PHP.

From front end I am calling login API to validate the user id and password and if authenticated then I am generating a token , storing it in a database and returning this to the client :

{"user":"usr1","status":"AUTHENTICATED","token":"56etXss32124hWZ31AAf"}

And I am storing that in cookie so that my front-end knows that the user is logged in.

Now I do not want to store the token in normal cookie. The user and status is ok to store in normal cookie and I have to store at least the status, to keep my logged in state alive even after page refresh .

I want to store the token in a session cookie or httponly cookie to make the transaction more secure. And also I want to set this token to httponly cookie so that when I make another API call to modify any user specified data this token is passed to my server and I can validate the user.

Can anyone please suggest me how to achieve this ?

0 Answers
Related