Generally, you can take anything Portswigger says about web security to the bank.
Generally, you can take anything Portswigger says about web security to the bank.
It is worse than useless because it makes you think you are secure.
XSS attackers are more likely to generate arbitrary requests to secure endpoints as you via JS than they are to send the cookie to themselves at 3AM so they can rush to craft requests.
And httponly does didly squat to prevent that.
Better is to focus entirely on santizing your output properly in the context it is outputted. And use whitelists, never blacklists.
And use whitelists, never blacklists.
Why?- If you get attacked in a way where the XSS would allow token exfiltration but are protected by HttpOnly, then the attacker is more likely to just grab data with your session cookie auth and POST that data over to their server using JS (or some other super-CSRF-like attack), so the HttpOnly limited the data you can protect to the token, which hardly matters at that point.
Is that a more fair understanding of the issue? Thanks for the correction here!