# Secure cookie configuration

**URL:** <https://meta.discourse.org/t/secure-cookie-configuration/132388>\
**Category:** Self-hosting\
**Created:** [November 1, 2019, 11:10am UTC](https://meta.discourse.org/t/secure-cookie-configuration/132388 "2019-11-01T11:10:21Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)\
**Post date:** [November 1, 2019, 4:53pm UTC](https://meta.discourse.org/t/secure-cookie-configuration/132388/5 "2019-11-01T16:53:05Z")

</div>

That is just the `destination_url` cookie, used only during the login flow to store where the user wanted to go, so we can send him there after the login. And since it’s read on the EmberJS app for routing, it can’t contain the `HTTP_ONLY` flag.

You can learn more about all cookies in Discourse at [(Deprecated) List of cookies used by Discourse](https://meta.discourse.org/t/list-of-cookies-used-by-discourse/83690)

---

_[View the full topic](https://meta.discourse.org/t/secure-cookie-configuration/132388)._
