I am trying to set up cookies with httpOnly to fight cross scripting.I tried to modify the response header, but that does not work. Is their any place in Jboss I can an evironment that would set the property. Thanks for any help --jvc--