This prevents the browser from reveal a session cookie, against XSS attacks and users from accidentally access a resource that exploits this flaw.