jac*_*des 29 cookies jsessionid java-ee
我想知道什么是host onlycookie.
在检索a时form auth,浏览器会在标题中显示一个JSESSIONID cookie host only.
Sil*_*Fox 52
首先,不可能foo.com设置可以读取的cookie bar.com.Host-only只保护example.comcookie不被读取bar.example.com.
从RFC 6265关于设置cookie及其Domain属性:
Run Code Online (Sandbox Code Playgroud)If the domain-attribute is non-empty: If the canonicalized request-host does not domain-match the domain-attribute: Ignore the cookie entirely and abort these steps. Otherwise: Set the cookie's host-only-flag to false. Set the cookie's domain to the domain-attribute. Otherwise: Set the cookie's host-only-flag to true. Set the cookie's domain to the canonicalized request-host.
以上可以通过"Host-only is default"来概括.也就是说,如果Domain未指定,则cookie只能由设置cookie的确切域读取.这可以通过Domain在设置cookie时设置属性来放宽.
例如,如果cookie设置为www.example.com并且Domain未指定属性,则将使用域设置cookie,www.example.com并且cookie将仅是主机cookie.
另一个例子:如果cookie被设置为www.example.com并且Domain属性被指定为example.com(因此cookie也将被发送foo.example.com),cookie将被设置为域example.com(或者可能.example.com是某些浏览器使用前面的RFC 2109中的点来表示不是仅限主机)并且cookie 不会是仅限主机的cookie.
第5.4节介绍了有关浏览器发送cookie标头的时间的发送:
Run Code Online (Sandbox Code Playgroud)The cookie's host-only-flag is true and the canonicalized request-host is identical to the cookie's domain. Or: The cookie's host-only-flag is false and the canonicalized request-host domain-matches the cookie's domain.
因此,发送带有域foo.example.com和host-onlyfalse 的cookie example.com.如果host-only为真,则foo.example.com仅发送给foo.example.com.
jac*_*des 11
主机只有饼干意味着该Cookie应该由浏览器来处理服务器只在同一主机/服务器,首先它发送给浏览器.
您不希望仅为广告系列发送此主机Cookie,因为它可能包含敏感信息.
| 归档时间: |
|
| 查看次数: |
28663 次 |
| 最近记录: |