Cookie
cookies, http cookie, session cookie, third-party cookieDefinitions
A small named value a server asks the browser to store and send back on every subsequent request to that origin — the mechanism that gives a stateless protocol a memory of who is asking
The attributes are the whole security story. HttpOnly keeps it out of JavaScript, so a cross-site scripting bug cannot read the session. Secure refuses to send it over plain HTTP. SameSite decides whether it rides along on a request another site initiated, which is what cross-site request forgery depends on. Domain and Path set the blast radius, and Max-Age sets how long a stolen one stays useful. A session cookie with the first three set correctly is a different object from one without them.
In privacy law and in practice, the thing a consent banner is asking about — though the rules are about storage and tracking generally, not about the cookie header specifically
GDPR and the ePrivacy Directive in the EU, and the CCPA in California, govern reading or writing anything on a reader’s device for a purpose that is not strictly necessary. Local storage and fingerprinting are covered the same way; naming the banner after cookies is a historical accident that lets a site claim compliance while tracking by another means.
How the web remembers you between two requests it is otherwise required to treat as strangers.
Avoid: storing anything in a cookie that you would not hand to whoever
borrows the laptop. It is sent on every matching request, it is readable
unless HttpOnly says otherwise, and it outlives the tab.