Alain Schneble writes: > I would be happy to arrange a patch to solve this issue, but would like > first to discuss which approach to choose: > > 1. Simply ignore any HttpOnly attribute/flag on a Set-Cookie header > value. Following the first approach above, I propose to apply this patch: