From what I understand, HttpOnly cookies cannot be read by client js but they are passed by the browser with any subsequent requests. If an attacker is able to
aaa-security-protocol
svg-edit
framebuffer
text-parsing
google-cloud-functions
synth
suitecrm
activation-function
ohdsi-omop
vmd
fresco
gitlab-ci-runner
rust-rocket
whm
websharper
shopify-app
eclipse-luna
anko
rails-generators
sqlsrv
fog
loose-typing
android-radiobutton
django-manage.py
jfrog-container-registry
filesystemexception
launcher-icon
choetl
h3
mysql-error-1045