freecoding.school100% FREE · NO SIGNUP
Await StationISSUE #21 of 26

cookies · document.cookie

PromissaVSRace Condition Rex
Promissa saysCookies are small strings sent with every request — set via document.cookie or HTTP headers.

Cookies (document.cookie) store tiny data the browser attaches to matching requests — historically for sessions. For auth, prefer server-set cookies with HttpOnly (hidden from JS, blocks XSS theft), Secure, and SameSite. Client-readable cookies suit non-sensitive prefs; for general storage, localStorage/IndexedDB are simpler.

Power-ups you unlock

Race Condition Rex attacks — common mistakes

Boss battleSet a non-sensitive preference cookie and read it back from document.cookie.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>document.cookie='theme=dark; SameSite=Lax';
document.getElementById('o').textContent='cookies: '+document.cookie;</script></body></html>
▶ Open the interactive comic issue
‹ IndexedDB · The Browser DatabaseHistory Api · PushState · ReplaceState ›