2 ms·
Bingo. "Auth Token" simply becomes "Session ID", and the backend then tracks anything it wants as part of the session. I don't see much of a solution other tha
by developer2 6y ago
Bingo. "Auth Token" simply becomes "Session ID", and the backend then tracks anything it wants as part of the session.
I don't see much of a solution other than making it a matter of policy, eg. Microsoft's "P3P" header. Otherwise authentication credentials need to be supplied with every request. Not a session id or token as a cookie, but the actual username and password being supplied with every request. Basically the old http basic auth, but with a more modern system to replace it.
I understand the core idea behind the EU's desire, but the fact is that cookies are absolutely required for login sessions, and it's impossible to allow users to opt out. The EU doesn't understand the tech behind the laws they are trying to enforce, and this is where it leads to. Absurdity.