This miss the "HttpOnly" part, which prevents javascript (think script injection vulnerability) from touching this part of the storage