Security Enhancement in CF 9.0.1
In the CF 9.0.1 list of What’s New and Changed, the last item listed in the “other enhancements” area is a small note that “CFID, CFTOKEN, and jsessionid are marked httpOnly”. This is a small but significant step in the right direction. What is httpOnly mean? Well, the OWASP website has a nice explanation. Basically [...]