4 ms·
The browser can have to cookies with the same name, and variations in path or domain, but still transmit both in a http request. This causes most cookie parsers
by shynrou 7y ago
The browser can have to cookies with the same name, and variations in path or domain, but still transmit both in a http request.
This causes most cookie parsers to make mistakes since they expect only one.
Also on the note of cookies, modern browser do not delete session or stale cookies if the browser was not closed properly, eg. the user just shutdown the system without closing the browser.
- aichbauer 7y agoI did not know that before. I mean of course you can differentiate between them because of the path and domain, but still this can cause problems. Do you have an example of when you would like to have the same cookie for different domains or paths? Is it most likely a problem that occurs when programmers create cookies for the wrong path or domain. Or would you say there is a use case for that?
- shynrou 7y agoThe server does not receive the path and domain infos so you cant differentiate at that point. Jeah, domain wise if you have a cookie set for example.com and test.example.com, if the user is on the later it would send both cookies. This may be wanted for a common login system. In general yes it can be avoided if potential conflicting apps use different cookie names by default.