6 ms·
I may be wrong here, but I think there's one good reason to use anything.example.com instead of example.com: with the naked domain, you can't have a separate do
by storborg 16y ago
I may be wrong here, but I think there's one good reason to use anything.example.com instead of example.com: with the naked domain, you can't have a separate domain for static assets which the client doesn't send the cookie to (for performance improvement). If you set a cookie with the domain example.com, it will still get sent to static.example.com.
Granted, you could use examplecdn.com or something, but then you have to register and manage more domains.
- apgwoz 16y agoIsn't that what the domain portion of the set-cookie header is for?
- seabee 16y agoIt gets propagated to subdomains, it doesn't restrict it to just the domain specified.
- apgwoz 16y agoYes, it gets propogated to subdomains, but the point was that if you have subdomain X.y.z, as long as you set the cookie for y.z, the cookie is valid for X.y.z and U.y.z.
- storborg 16y agoMy point was that you don't want the cookie to be sent to other subdomains, so you'd actually want to set the domain to X.y.z. You can't do that if you're web domain is y.z.