[ 
https://issues.apache.org/jira/browse/SHINDIG-1110?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12730832#action_12730832
 ] 

Chris Chabot commented on SHINDIG-1110:
---------------------------------------

I'm not entirely sure what the right-thing-to-do is, the proposal to define 
this in the spec wasn't accepted for 0.9, as such there's no clear directions 
on what exactly we expect it to do. On the one hand cookies are terribly useful 
to support, on the other hand since in some social sites all the gadgets are on 
the same domain, it's also a security risk. The conclusion was also that 
setting headers in makeRequest was undesirable and a security risk.. so that 
limits the usefulness of it quite a bit as well.

I'll ask around and see what other people's opinions on this is

> ProxyHandler fetchJson should forward Set-Cookie header
> -------------------------------------------------------
>
>                 Key: SHINDIG-1110
>                 URL: https://issues.apache.org/jira/browse/SHINDIG-1110
>             Project: Shindig
>          Issue Type: Bug
>          Components: PHP
>    Affects Versions: 1.1-M1
>            Reporter: Johan Euphrosine
>         Attachments: proxy-handler-fetch-json-set-cookie.patch
>
>
> Hi,
> It seems that ProxyHandler fetchJson doesn't forward Set-Cookie header.
> http://groups.google.com/group/opensocial-and-gadgets-spec/browse_thread/thread/7ef764a779257c48
> http://groups.google.com/group/opensocial-and-gadgets-spec/browse_thread/thread/51b016b80e9d21e6

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to