Exercise 2: HttpOnly Present vs. Absent — Possible Solution ==================================================================== THE TWO REAL RESPONSES ------------------------------ r_on = Response() r_on.set_cookie('session_id', 'abc', http_only=True) print(dict(r_on.headers)['Set-Cookie']) r_off = Response() r_off.set_cookie('session_id', 'abc', http_only=False) print(dict(r_off.headers)['Set-Cookie']) VERIFIED, REAL RESULT ------------------------------ http_only=True: session_id=abc; HttpOnly; Path=/; SameSite=Lax http_only=False: session_id=abc; Path=/; SameSite=Lax The literal string "HttpOnly" is present in exactly one of the two real header values and completely absent from the other - the flag either is or isn't on the wire, nothing in between. WHAT AN ATTACKER'S INJECTED SCRIPT COULD AND COULDN'T DO ------------------------------ Chapter 4's own real, verified XSS finding showed a naive, unescaped template letting a genuine