Talk:HttpOnly

Tomcat configuration
Tomcat versions from 5.5.28 and 6.0.19 support the HttpOnly cookie option.

This is configured in the conf/context.xml file:

 ... 