Cookie
- The client sends a request to the server without cookie.
- The server reponses with the cookie by setting
Set-cookieheader. - The client requests with the cookie by setting the
Cookieheader.

Cookie attributes
-
Expires, Max-Age
They set the expired time.
Expiresis a timestamp,Max-Ageis an interval.Max-Agehas the higher priority. -
Domain, Path
They must match those in the request.
-
HttpOnly
Only Http can read the cookie. DOM API, like
document.cookiecan't visit it. -
SameSite
-
SameSite=Strict: Cookies cannot be sent across sites along with the redirect link. -
SameSite=Lax:GET/HEADis allowed,POSTNOT.
-
-
Secure
The cookie is only used in HTTPS.