Req #70000 [Sus]: craig@craigfrancis.co.uk

From: Date: Mon, 06 Jul 2015 10:58:43 +0000
Subject: Req #70000 [Sus]: craig@craigfrancis.co.uk
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194150@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70000&edit=1 ID: 70000 User updated by: craig at craigfrancis dot co dot uk Reported by: craig at craigfrancis dot co dot uk -Summary: First-Party-Only Cookies +Summary: craig@craigfrancis.co.uk Status: Suspended Type: Feature/Change Request Package: HTTP related Operating System: N/A PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Agreed, it was more to start the discussion now (although perhaps not waiting for too many implementations, as I know it takes a while for the likes of RedHat to get new versions of PHP into a shipping product). And I agree that the setcookie signature is getting a bit too long: setcookie('name', 'value', 0, '/', 'example.com', true, true, true); Out of interest, to support this (and potentially other) flags now, I suspect it will involve re-creating the setcookie() function with a header() call? Previous Comments: ------------------------------------------------------------------------ [2015-07-06 10:42:11] requinix@php.net Most recent draft: https://tools.ietf.org/html/draft-west-first-party-cookies-03 The RFC is still in draft, Chromium has had some back-and-forth regarding an actual implementation (or so I read in the revision history), and apparently there's been some question regarding Chromium's behavior versus Firefox's https://groups.google.com/a/chromium.org/d/topic/blink-dev/ZvMEJMSU6po/discussion Supporting First-Party-Only seems like a no-brainer to me, but I'm thinking we'd best wait until the proposal reaches RFC status. Maybe even until it reaches the major browsers. (setcookie's signature is getting unwieldy - maybe there can be some additional work with it?) ------------------------------------------------------------------------ [2015-07-06 09:52:13] craig at craigfrancis dot co dot uk Description: ------------ Google Chrome is currently considering implementing First-Party-Only Cookies. https://code.google.com/p/chromium/issues/detail?id=459154 https://tools.ietf.org/html/draft-west-first-party-cookies-01 https://www.chromestatus.com/feature/4672634709082112 This is an interesting security feature, so should the setcookie() function be updated to also support this? http://php.net/setcookie bool setcookie ( string $name [, string $value [, int $expire = 0 [, string $path [, string $domain [, bool $secure = false [, bool $httponly = false [, bool $firstonly = false ]]]]]]] ) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70000&edit=1

« previous php.bugs (#194150) next »