Discuss and resolve questions on Liquid, JavaScript, themes, sales channels, and site speed enhancements.
Hi all,
We recently conducted a pen-test on our Shopify storefront via a third party security company. They identified some cookies, flagged as being used for session management, which do not have the HttpOnly attribute set.
The cookies flagged were:
Can someone confirm whether these cookies are actually used for session management and whether them lacking HttpOnly can lead to theft via cross-site scripting (XSS) attacks?
Learn how to build powerful custom workflows in Shopify Flow with expert guidance from ...
By Jacqui May 7, 2025Did You Know? May is named after Maia, the Roman goddess of growth and flourishing! ...
By JasonH May 2, 2025Discover opportunities to improve SEO with new guidance available from Shopify’s growth...
By Jacqui May 1, 2025