Legoktm added a comment.

In https://phabricator.wikimedia.org/T107602#1499998, @Smalyshev wrote:

> The service does not need to access them but I'm not sure how we can avoid 
> them being sent... Maybe have some varnish rule to strip them? I see that 
> "interesting" cookies are HTTP only, so it looks less problematic.


@bblack, is that possible?

Another alternative could be to have CentralAuth set the cookie for 
"www.wikidata.org". Only downside is that test.wikidata.org users would have to 
visit that wiki once and reload the page to get logged in...but it's a test 
wiki.


TASK DETAIL
  https://phabricator.wikimedia.org/T107602

EMAIL PREFERENCES
  https://phabricator.wikimedia.org/settings/panel/emailpreferences/

To: Legoktm
Cc: Legoktm, gerritbot, Smalyshev, BBlack, Joe, daniel, RobLa-WMF, Aklapper, 
aude, JanZerebecki, JeroenDeDauw, MrStradivarius, waldyrious, Krenair, 
MBlissett, bd808, Laddo, Addshore, Matanya, jkroll, Wikidata-bugs, Jdouglas, 
RobH, Manybubbles, mark, faidon, fgiunchedi, Dzahn, chasemp, Malyacko, P.Copp



_______________________________________________
Wikidata-bugs mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikidata-bugs

Reply via email to