Enabling the HTTPOnly parameter
Enabling the HTTPOnly attribute prevents malicious scripts from stealing a user's session identity.
About this task
Procedure
- Launch IBM Cognos Administration.
- On the Status tab, click System.
- In the upper left corner of the Scorecard pane, click the arrow to view the Change view menu, point to Services. The Set properties page appears.
- Click to enable the Disallow browser scripts from accessing the passport session cookie.
- Click OK.