Skip to content

Commit

Permalink
RFC6265bis: '__Host-' requires explicit 'Path=/'. Closes #222.
Browse files Browse the repository at this point in the history
  • Loading branch information
mikewest committed Aug 7, 2017
1 parent 5119073 commit 09beb95
Showing 1 changed file with 4 additions and 1 deletion.
5 changes: 4 additions & 1 deletion draft-ietf-httpbis-rfc6265bis.md
Expand Up @@ -1445,7 +1445,8 @@ user agent MUST process the cookie as follows:

2. The cookie's host-only-flag is true.

3. The cookie's path is `/`.
3. The cookie-attribute-list contains an attribute with an attribute-name
of "Path", and the cookie's path is `/`.

17. If the cookie store contains a cookie with the same name, domain, and
path as the newly-created cookie:
Expand Down Expand Up @@ -2018,6 +2019,8 @@ Specification document:
* Merged the recommendations from {{I-D.ietf-httpbis-cookie-same-site}}, adding
support for the `SameSite` attribute.

* Clarified that a `Path` attribute is required for `__Host-` cookie prefixes.

# Acknowledgements

This document is a minor update of RFC 6265, adding small features, and
Expand Down

0 comments on commit 09beb95

Please sign in to comment.