logoalt Hacker News

9rxyesterday at 7:03 PM0 repliesview on HN

If it weren't already in the same domain you wouldn't be able to read a non-HttpOnly cookie anyway, so that's moot.