On Thu, 17 Jul 2008 10:36:00 +0200, Gerfried Fuchs wrote: > > "RFC 2109 reccomends that the minimal cookie size supported by the > > client is 4096 bytes. This has become a pretty standard value, and if > > your server sends larger cookies than that it's considered a no-no." > > 1.'reccomends' should be 'recommends'
Thanks for spotting this; already fixed in our subversion repository.
> > 2. More importantly, 'minimal' should in all likelihood be 'maximum'.
I'm not so sure about that point. RFC 2109 [0] says in "6.3
Implementation limits":
Furthermore, general-use user agents should provide each of the
following minimum capabilities [..]
* at least 4096 bytes per cookie (as measured by the size of the
characters that comprise the cookie non-terminal in the
syntax description of the Set-Cookie header) [..]
User agents created for specific purposes or for limited-capacity
devices should provide at least 20 cookies of 4096 bytes,
As I understand this section, "minimal cookie size" seems quite ok.
Other comments?
Cheers,
gregor
[0]
http://www.ietf.org/rfc/rfc2109.txt
--
.''`. http://info.comodo.priv.at/ | gpg key ID: 0x00F3CFE4
: :' : debian gnu/linux user, admin & developer - http://www.debian.org/
`. `' member of https://www.vibe.at/ | how to reply: http://got.to/quote/
`- NP: Joan Baez: I Shall Be Released
signature.asc
Description: Digital signature

