Ch. 20 · Networking

HTTP Cookies, Scope and Browser Delivery

HTTP Cookies, Scope and Browser Delivery. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

Cookie delivery depends on scope and attributes such as domain, path, Secure and SameSite. Server authentication must validate the received credential.

Before you start

You should understand clients, servers, IP addresses and ports. Follow a request through name resolution, connection establishment and application exchange. Distinguish protocol guarantees from deployment policy, and use observations from the relevant layer rather than guessing from one browser error message.

The practical goal is to reason through this situation: A cookie scoped to one path may not accompany another endpoint. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Choose delivery scope

Domain and path determine which requests receive the cookie.

Step 2: Use transport and access attributes

Secure and HttpOnly address different exposure mechanisms.

Step 3: Model ambient credentials

SameSite and CSRF strategy must match actual browser behavior.

Worked scenario

A cookie scoped to one path may not accompany another endpoint.

A session cookie scoped to /account may not accompany /api/orders, making a valid login appear absent there. HttpOnly prevents ordinary script access to the cookie but does not itself prevent the browser from sending it on every eligible request. The server still validates session expiry and authorization.

Common mistake

HttpOnly limits script access but does not independently prevent every forged request.

Verify the behavior

Test intended and unintended paths, secure transport, expiry and cross-site request behavior.

Interview exercise

Design a session cookie.

Answer and reasoning

Use deliberate transport and scope attributes, expiration and server validation, with a CSRF strategy matching browser delivery behavior.

Continue learning

Compare the scenario with the Networking interview questions and test your understanding with the Networking MCQs. For terminology and implementation details, consult the reference material.

More in Networking

read ✓Networking · mid

Networking: HTTP Redirects

Choose between 301, 302, 307 and 308, know which preserve the request method, and avoid caching and loop mistakes.

~2 min readread →
read ✓Networking · mid

HTTP Cache-Control and Response Freshness

HTTP Cache-Control and Response Freshness. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readread →
read ✓Networking · easy

HTTP Methods, Safety and Idempotence

HTTP Methods, Safety and Idempotence. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readread →
esc