Just a quick project I did to verify some concerns with extensions in chrome having access to all secure/httpOnly cookies (on domains they have requested access to)
main.html 285B

  1. <!DOCTYPE html>
  2. <html>
  3. <head>
  4. <meta charset="utf-8" />
  5. <title>Main</title>
  6. </head>
  7. <body>
  8. <div style="width: 400px; height 400px;"><h1>Your facebook (not-so)secure cookies<h2>
  9. <pre id="cookie-jar"></pre>
  10. <script src="main.js"></script>
  11. </div>
  12. </body>
  13. </html>