From what I understand, HttpOnly cookies cannot be read by client js but they are passed by the browser with any subsequent requests. If an attacker is able to
nevpnmanager
nservicebus
pyhdf
syntastic
drop-database
google-fusion-tables
redhawksdr
visual-c#-express-2010
azure-app-service-plans
mercure
cohesion
ngx-clipboard
mscoco
sqldatetime
goofys
newsapi
windows-themes
eventsource
keyset-pagination
node-html-pdf
ping
metafile
gesture-detection
member-functions
c++20
number-formatting
api-authorization
twincat-ads-.net
autodesk-forge
docx-to-pdf-conversion