什么是主机唯一的cookie?

jac*_*des 29 cookies jsessionid java-ee

我想知道什么是host onlycookie.

在检索a时form auth,浏览器会在标题中显示一个JSESSIONID cookie host only.

Sil*_*Fox 52

首先,不可能foo.com设置可以读取的cookie bar.com.Host-only只保护example.comcookie不被读取bar.example.com.

从RFC 6265关于设置cookie及其Domain属性:

If the domain-attribute is non-empty:

  If the canonicalized request-host does not domain-match the domain-attribute:

    Ignore the cookie entirely and abort these steps.

  Otherwise:

    Set the cookie's host-only-flag to false.

    Set the cookie's domain to the domain-attribute.

Otherwise:

  Set the cookie's host-only-flag to true.

  Set the cookie's domain to the canonicalized request-host.
Run Code Online (Sandbox Code Playgroud)

这意味着什么

以上可以通过"Host-only is default"来概括.也就是说,如果Domain未指定,则cookie只能由设置cookie的确切域读取.这可以通过Domain在设置cookie时设置属性来放宽.

例如,如果cookie设置为www.example.com并且Domain未指定属性,则将使用域设置cookie,www.example.com并且cookie将仅是主机cookie.

另一个例子:如果cookie被设置为www.example.com并且Domain属性被指定为example.com(因此cookie也将被发送foo.example.com),cookie将被设置为域example.com(或者可能.example.com是某些浏览器使用前面的RFC 2109中的点来表示不是仅限主机)并且cookie 不会是仅限主机的cookie.

第5.4节介绍了有关浏览器发送cookie标头的时间的发送:

         The cookie's host-only-flag is true and the canonicalized
         request-host is identical to the cookie's domain.
      Or:
         The cookie's host-only-flag is false and the canonicalized
         request-host domain-matches the cookie's domain.
Run Code Online (Sandbox Code Playgroud)

因此,发送带有域foo.example.com和host-onlyfalse 的cookie example.com.如果host-only为真,则foo.example.com仅发送给foo.example.com.

  • 刚刚在客户的网站上遇到了这个问题,然后去查了一下。您的评论清晰易懂。为它的道具。 (3认同)
  • @sparrowrt 这最终(在您发表评论后)在 IE 和 Edge 中得到修复:“通过 Windows 10 RS4(2018 年 4 月),Edge 和 Internet Explorer 都与其他浏览器匹配。” (来自您链接到的常见问题解答) (2认同)

jac*_*des 11

主机只有饼干意味着该Cookie应该由浏览器来处理服务器只在同一主机/服务器,首先它发送给浏览器.

您不希望仅为广告系列发送此主机Cookie,因为它可能包含敏感信息.

  • @MyUsername112358 你把它搞反了。SilverLightFox 的答案在这之后两年多才公布。 (8认同)