Forum Discussion
Abhishek_128328
Nimbostratus
Dec 10, 2013expire httpOnly cookie is request
can i expire a HttpOnly cookie in request with the below rule
HTTP::cookie remove ""
IheartF5_45022
Nacreous
Dec 10, 2013Hi. If you just want to prevent a client cookie from reaching the server then HTTP::cookie remove "mycookie" in HTTP_REQUEST will work fine.
If you actually want to expire a cookie from the client to stop it from sending it in subsequent requests, then you need to set the cookie Expires date to the past;-
when HTTP_RESPONSE {
HTTP::header insert Set-Cookie "mycookie=xx; Path=/; Expires=Thu, 01 Jan 1970 00:00:01 GMT; HttpOnly"
}
Note that this example assumes the cookie was set on the current domain, not a parent domain, and that the Path was /.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects