Skip to content
This repository was archived by the owner on Nov 6, 2023. It is now read-only.

rebased PC-BSD.xml (fixed #5608)#5639

Merged
jeremyn merged 5 commits intoEFForg:masterfrom
J0WI:5608
Sep 1, 2016
Merged

rebased PC-BSD.xml (fixed #5608)#5639
jeremyn merged 5 commits intoEFForg:masterfrom
J0WI:5608

Conversation

@J0WI
Copy link
Copy Markdown
Contributor

@J0WI J0WI commented Jul 13, 2016

No description provided.

@jeremyn
Copy link
Copy Markdown
Contributor

jeremyn commented Aug 29, 2016

@J0WI
Copy link
Copy Markdown
Contributor Author

J0WI commented Aug 30, 2016

I would keep the insecure cookie comment, because there is no drawback and dev may get aware of the issue.
I had to remove the generic securecookie rule, because ^ and www are not fully secureable. The other hosts aren't serving any cookies.

@jeremyn
Copy link
Copy Markdown
Contributor

jeremyn commented Aug 30, 2016

Do you mean that some of the ^/www cookies are not isSecure even with the generic securecookie? It doesn't break anything though, right?

@J0WI
Copy link
Copy Markdown
Contributor Author

J0WI commented Aug 30, 2016

If you set the secure flag on the cookies but you can't access the site over https (because of mixed content), the site is not able to read the cookies.

@jeremyn
Copy link
Copy Markdown
Contributor

jeremyn commented Aug 30, 2016

I think I understand. Are we running into a securecookie problem here because www.pcbsd.org is only partially allowed?

Also, for the comment, the drawback of the comment is that we are repeating ourselves between it and the securecookie tag itself. But if you want to leave the comment in, that's fine.

@J0WI
Copy link
Copy Markdown
Contributor Author

J0WI commented Sep 1, 2016

I think I understand. Are we running into a securecookie problem here because www.pcbsd.org is only partially allowed?

Exactly.

@jeremyn jeremyn merged commit 7fd2ed2 into EFForg:master Sep 1, 2016
@jeremyn
Copy link
Copy Markdown
Contributor

jeremyn commented Sep 1, 2016

Thanks, merged.

@J0WI J0WI deleted the 5608 branch September 1, 2016 14:10
@jeremyn jeremyn removed their assignment Sep 10, 2016
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants