No subject
Tue Nov 13 08:16:38 EST 2012
Geoffrey Myers<br>
<br>
</div><div class=3D"HOEnZb"><div class=3D"h5">On Apr 26, 2013, at 4:44 PM, =
Phil Turmel <<a href=3D"mailto:philip at turmel.org">philip at turmel.org</a>&=
gt; wrote:<br>
<br>
><br>
> On 04/26/2013 03:29 PM, Geoffrey Myers wrote:<br>
>> So, still wrestling with this. Scenario:<br>
>><br>
>> 1. Frame of page creates a cookie. Another frame in that page retr=
ieves all cookies, does not see the new cookie.<br>
>><br>
>> 2. Totally separate page on another tab creates a cookie. Both fra=
mes of other tab see this cookie.<br>
>><br>
>> Why aren't the cookies created in frame 1 seen by frame 2?<br>
>><br>
>> 2nd tab does not see the cookie created by first frame either.<br>
>><br>
>> Cookies are not page specific. What is going on?<br>
><br>
> This isn't correct. =C2=A0The 'path' component of a cookie=
makes it at least<br>
> partially page-specific, and the domain of the cookie triggers many<br=
>
> visibility restrictions. =C2=A0Some of those are explained in the<br>
> specification, but other restrictions have been added to browsers to<b=
r>
> limit cross-site hacks.<br>
><br>
> Short of letting others look at the pages in question, it will probabl=
y<br>
> be difficult to help. =C2=A0 At least a trace of the request and respo=
nse<br>
> headers for each page and frame would be needed.<br>
><br>
> (I'm definitely not an expert on these topics, but I can spot some=
of<br>
> the common flaws if they are staring me in the face.)<br>
><br>
> Phil<br>
><br>
> _______________________________________________<br>
> Ale mailing list<br>
> <a href=3D"mailto:Ale at ale.org">Ale at ale.org</a><br>
> <a href=3D"http://mail.ale.org/mailman/listinfo/ale" target=3D"_blank"=
>http://mail.ale.org/mailman/listinfo/ale</a><br>
> See JOBS, ANNOUNCE and SCHOOLS lists at<br>
> <a href=3D"http://mail.ale.org/mailman/listinfo" target=3D"_blank">htt=
p://mail.ale.org/mailman/listinfo</a><br>
<br>
_______________________________________________<br>
Ale mailing list<br>
<a href=3D"mailto:Ale at ale.org">Ale at ale.org</a><br>
<a href=3D"http://mail.ale.org/mailman/listinfo/ale" target=3D"_blank">http=
://mail.ale.org/mailman/listinfo/ale</a><br>
See JOBS, ANNOUNCE and SCHOOLS lists at<br>
<a href=3D"http://mail.ale.org/mailman/listinfo" target=3D"_blank">http://m=
ail.ale.org/mailman/listinfo</a><br>
</div></div></blockquote></div><br><br clear=3D"all"><br>-- <br>-- <br>Jame=
s P. Kinney III<br><i><i><i><i><br></i></i></i></i>Every time you stop a sc=
hool, you will have to build a jail. What you=20
gain at one end you lose at the other. It's like feeding a dog =
on his=20
own tail. It won't fatten the dog.<br>
- Speech 11/23/1900 Mark Twain<br><i><i><i><i><br><a href=3D"http:/=
/electjimkinney.org" target=3D"_blank">http://electjimkinney.org</a><br><a =
href=3D"http://heretothereideas.blogspot.com/" target=3D"_blank">http://her=
etothereideas.blogspot.com/</a><br>
</i></i></i></i>
</div>
--047d7b3a84369a4f1004db9716bb--
More information about the Ale
mailing list