This means that the client will only send this cookie over a secure (HTTPS) connection. This means that you need to redirect the user to a secure URL so that the cookie is sent to the server.
You can set a secure cookie over an insecure connection, although you obviously shouldn't (otherwise the cookie value can be sniffed). Since a secure cookie can be altered by an insecure connection, you cannot trust that the cookie value was not corrupted by a third party that intercepted and modified the contents of an insecure HTTP request to your site. Therefore, depending on how you use the secure cookie, you may need to check its contents.
source
share