Site Server General - cookies dropped to multiple domain levels

This is Interesting: Free IT Magazines  
Home > Archive > Site Server General > February 2004 > cookies dropped to multiple domain levels





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author cookies dropped to multiple domain levels
erin

2004-02-04, 10:39 am

I'm a QA Engineer for a company that recently changed the domain level
at which the session and nonsession cookies are dropped. For example,
the cookies were dropped at ".y.x.com", but have been recently changed
to ".x.com". What I'm concerned with is that there are still
nonsession cookies on the end users machines that contain persistent
sign in information in the old ".y.x.com" cookies. Since the
nonsession cookies are both dropped against a form of ".x.com", and
two cookies of the same name exist at the different domain levels, are
both sent to the code when it requests reading the cookies?

I was under the impression that the code would be written to just read
the ".x.com" cookies. However, one of the developers had mentioned
that the browser would send both old and new cookies. Does anyone
know if this is true?

Ultimately I'm trying to find out what ill side effects could occur if
both cookies are being read. At some point the old cookie could get
out of synch with the new cookie and the end user could see
conflicting user experiences.

Thanks for any thoughts on this...

-erin
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com