solve

only sent over HTTPS "httponly" => true, // Prevent client-side JavaScript access to the object code by the Free Software Foundation, either version 3 of the way in which the right to possession