I would like to see if squid can modify headers on outbound web pages to add the httpOnly flag to specific session cookies. Old web app server does not know how to add httpOnly flag to session cookie. Squid 2.7 is used in front of web app server in reverse proxy mode.