3 ms·
They are a good fallback, I think he is talking about using things such as Local storage, session storage, or global storage. Since the site is their mobile sit
by dkroy 14y ago
They are a good fallback, I think he is talking about using things such as Local storage, session storage, or global storage. Since the site is their mobile site I see no reason why they aren't using the new technology available to us since most mobile devices would be able to use it. DOM storage seems to be a better fit for shopping carts than cookies anyways.
- pilif 14y agoIt's not about the shopping cart. It's about all the session data, especially for authentication. While you could use Dom storage for storing a session ID, you would have to send that through to the server with every request which you get for free with cookies. Additionally, cookies can be marked as http only or even as secure, making it very hard to lose the token by virtue of a fire sheep like, or even just XSS attack. For that reason, I personally would prefer a site using (session) cookies to one hacking it via DOM storage any day. And finally, depending on the store you might want to persist the shopping cart between visits- likely across machines. Thus, the cart should be stored on the server and not in DOM storage.
- dkroy 14y agoCookies are stored on the client just like DOM Storage, so nothing is free when it comes to requests and communicating with the server. I understand that both still have their place. Though I generally prefer to use DOM Storage for most things now depending on the use case. I also complete agree about keeping server-side session data.
- pilif 14y agowith "free" I meant without additional effort for the developer. When you set a cookie with a Set-Cookie header, the client will automatically send the cookie with all further requests. When you put the session-ID somewhere in DOM storage, you have to manually amend all requests with that session-ID - either by appending it as a get parameter or, when you do nothing but AJAX, as an additional request header - but whatever you do, it's considerably more effort. Also, looking at our logs, I see way more users with DOM storage disabled than with cookies disabled, but that might just be my user base.
- dkroy 14y agoAlright, thanks for the clarification on "free", I realized that is what you might have meant after posting. That last bit about your logs is surprising, thanks for that bit of info. I may need to go do the same. Either way I use a storage wrapper so I am accommodating both types of users.