4 ms·
- To reduce the attack surface In the event of site with a *.gov.uk subdomain getting compromised at least it won't now be able to steal auth cookies for inter
by dndvr 4y ago
- To reduce the attack surface
In the event of site with a *.gov.uk subdomain getting compromised at least it won't now be able to steal auth cookies for internal services
- to keep test/stage as faithful a copy of prod as possible they will have a totally separate but the same DNS set up/CDN set up/ load balancing etc. Theoretically the only difference would need to be one routing rule rather than stuff that might start creating edge case bugs with certs/cookies etc where there are different numbers of segments in domains. Also allows for more certainty/confidence when something is tested in a lower environment that it will work when promoted to prod