Robuta

https://www.eclipse.org/lists/jetty-users/msg01215.html
jettyusershttponlysecurecookieflags
https://www.educative.io/courses/web-application-security-everyday-software-engineer/javascript-cant-touch-this
Learn how to protect HTTP cookies from JavaScript access using the HttpOnly flag to strengthen web app security against XSS attacks and session hijacking.
http cookiessecuringhttponlypreventxss
https://support.mozilla.org/zu/questions/1449609
express sessionsusingnodesetcookie