Zitat von Donald Stufft <donald.stu...@gmail.com>:

Sadly, no browser follows this logic, and domain=example.com is exactly equivalent to domain=.example.com. There is no way to limit cookies to a single DNS name only, other than by not specifying domain= value at all - and even this does not work in Microsoft Internet Explorer; likewise, there is no way to limit them to a specific port.

I see. Still, it's not a problem at the moment; "python.org" does not issue
cookies. Even for the new site, it should be possible to find a secure solution
that doesn't involve shutting down packages.python.org.

Regards,
Martin


_______________________________________________
Catalog-SIG mailing list
Catalog-SIG@python.org
http://mail.python.org/mailman/listinfo/catalog-sig

Reply via email to