I would like to know what is a host only cookie.
host only
While retrieving a form auth, browser gets in the headers a JSESSIONID cookie shown as
form auth
The cookie's host-only-flag is true and the canonicalized request-host is identical to the cookie's domain.
http://tools.ietf.org/html/rfc6265#section-5.4