Ensure cookies are only sent over HTTPS "httponly" => true, // Ensure cookies are only sent over HTTPS "httponly" => true, // Prevent client-side JavaScript access to the