Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The documentation states that the shown approach can retrieve httpOnly cookies, but the provided JavaScript cannot do that. This is dangerous because users may rely on incorrect security assumptions, build tooling that mishandles session material, or attempt broader cookie exfiltration in authenticated browser sessions under the false belief that the example is sanctioned and complete.
