Httponly prevents xss
What does httponly do? Htyponly is to prevent xss vulnerabilities to steal your cookie. How to set it up? It's simple.
Setcookie ("test", 'without httponly',time () + 3600mm 24, ", 0)
Setcookie ("test1", "with httponly", time () + 3600mm 24, ",", 0jue 1)
You cannot read it using the [xss_clean] test1.