>>> Naveen Chandra <[EMAIL PROTECTED]> 08-Sep-00 2:39:39 AM >>>

>As Lara suggested I used request.getHeader("Cookie");
>in my servlet and it gave me the complete name value pair only,
>with semicolon (;) as the seperator, of cookies in my cookie file.

I think the answer is "you should know what the domain is if you get
the cookie".

The domain specifier is an instruction to the browser to only send
the cookie to clients in the domain.

Thus if you get the cookie you can easily find out what domain it was
associated with (because it was the domain you belong to!).

Of course that's a simplistic implementation - what if you have
multiple domains on a server? But  I suspect someone, somewhere, had a
security issue with sending the domain back in the request (goodness
knows why since cookies are completly insecure anyway).


Nic

___________________________________________________________________________
To unsubscribe, send email to [EMAIL PROTECTED] and include in the body
of the message "signoff SERVLET-INTEREST".

Archives: http://archives.java.sun.com/archives/servlet-interest.html
Resources: http://java.sun.com/products/servlet/external-resources.html
LISTSERV Help: http://www.lsoft.com/manuals/user/user.html

Reply via email to