Skip to content
This repository has been archived by the owner on Apr 22, 2022. It is now read-only.

Validate cookie domain configuration #123

Open
asnare opened this issue Mar 9, 2016 · 0 comments
Open

Validate cookie domain configuration #123

asnare opened this issue Mar 9, 2016 · 0 comments

Comments

@asnare
Copy link
Member

asnare commented Mar 9, 2016

Basic validation of the cookie domain configuration can be done, but isn't currently. Specifically, the cookie domain for a browser-based source should either be not present or contain a period (.).

(Issue #121 described a situation where a confusing outcome could have been prevented if this rule was evaluated on startup.)

The only cookie domain that I can think of that wouldn't work here is localhost for testing, but that's an edge case and unnecessary because the default of no setting will do the right thing.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

1 participant