Philip Semanchuk wrote: > On Tue, Mar 13, 2012 at 11:40 AM, Benjamin Lau > <[email protected]> wrote: >> You should probably add your voice to the ticket increasing the >> pressure to actually get this patch included in the core as well. :-) > > Good advice.
Nah, won't work ;) That patch actually looks pretty good, and I have had some more exposure to HTTP-only cookies since the ticket was filed, so I think it's a good idea. I'll apply it, probably later tonight or tomorrow. One thing I'm not quite sure, should the attribute be applied to all cookies, or only to the auth cookie? And about 0.13, you'll have to wait and see. I don't give any estimates anymore, as I have lost all credibility on the subject anyway. -- Remy
signature.asc
Description: OpenPGP digital signature
