Index: C:/Documents and Settings/Jim/workspace/tomcat-trunk/java/org/apache/tomcat/util/http/ServerCookie.java =================================================================== --- C:/Documents and Settings/Jim/workspace/tomcat-trunk/java/org/apache/tomcat/util/http/ServerCookie.java (revision 642698) +++ C:/Documents and Settings/Jim/workspace/tomcat-trunk/java/org/apache/tomcat/util/http/ServerCookie.java (working copy) @@ -247,7 +247,8 @@ String domain, String comment, int maxAge, - boolean isSecure ) + boolean isSecure, + boolean httpOnly) { StringBuffer buf = new StringBuffer(); // Servlet implementation checks name @@ -307,6 +308,10 @@ buf.append ("; Secure"); } + if (httpOnly) { + buf.append ("; HttpOnly"); + } + headerBuf.append(buf); }