Forum: Community Center


Subject: cookie domain defaulting to $ENV{SERVER_NAME}

_dodger opened this issue on Sep 17, 2002 ยท 3 posts


_dodger posted Tue, 17 September 2002 at 3:28 PM

No worries.

BTW, the one restriction is that there has to be more than one dot if the dot is the first character. That is to say, 'renderosity.com' is fine, but doesn't get sent to www.renderosity.com. '.renderosity.com' is fine, and gets sent to www.renderosity.com and renderosity.com.

Just .com, however, is ignored, and treated as if SERVER_NAME was the setting. This is to prevent sharing of cookies between domains which is a security risk. If it wasn't disallowed, one could set a cookie for any .com domain, whcih would not only be bad, it would also slow down the Internet. B^)