From what I understand, HttpOnly cookies cannot be read by client js but they are passed by the browser with any subsequent requests. If an attacker is able to
chef-solo
automapper-6
ng-packagr
email-forwarding
launcher
transit-gateway
smoke-testing
federated-identity
naos-project
caemitterlayer
arbitrary-precision
private-network
qdap
equational-reasoning
oracle-cloud-functions
zipper
bootable
junit-runner
spring-validator
qdial
structured-text
memory-address
passlib
oversampling
vue-dynamic-components
gedmo-loggable
openshift-origin
tor-browser-bundle
vert.x
android-assetmanager