From: Marty Alchin <gulop...@gmail.com>
Date: Thu, 24 Sep 2009 15:41:59 -0400
Local: Thurs, Sep 24 2009 3:41 pm
Subject: Re: Adding signing (and signed cookies) to Django core
> Also, does the name of a cookie factor into the cookie length limits? Also, just to throw this out there for the sake of compleness: could > My reading of RFC 2109 says yes, but it'd be worth verifying, since it > would cut down on the usable value space. With your compressed base64 > stuff, that's not as big of a problem, but still something to look > into. the signature be stored under a separate name, rather than being bundled with the original cookie itself? Set-Cookie: key=value It seems like this could address a couple issues at once. * There's a clear distinction between signed and unsigned cookies, so * The key/value pair remains unchanged, so things like Google Since there may be an upper limit on the number of allowed cookies, I'm not sure how many cookies people use on a regular basis, and this At least now it's been recorded for future reference. (Hello, future -Gul You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||