tomcat-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Remy Maucherat <>
Subject Re: Cookie issues
Date Wed, 11 Nov 2009 22:01:47 GMT
On Wed, 2009-11-11 at 16:45 -0500, Mark Thomas wrote:
> I really do loath cookies right now. I've pulled the proposed patches for 5.5.x
> and 6.0.x until I (or someone else) can take a look at this.

I do too. v0 cookies is 15 years old stuff that Netscape hacked out of
thin air without thinking at all, and seemingly nobody wants to upgrade
since then :(

The examples in the v1 spec (even the first one) are nice (everything is
always quoted, it's easy and it avoids problems ...), but the problems
occur if you try to enforce it (because the security folks ask for it)
and have to keep v0 support at the same time.


To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message