Re: [VOTE] Same Site Cookie RFC
| From: | Andrey Andreev | Date: | Sat, 21 Jul 2018 22:26:28 +0000 |
| Subject: | Re: [VOTE] Same Site Cookie RFC | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-102944@lists.php.net to get a copy of this message | ||
Hi,
On Thu, Jul 19, 2018 at 12:00 AM, Pedro Magalhães <mail@pmmaga.net> wrote:
>
> With this being said, would anyone oppose an implementation where all the
> options (including lifetime) are included in the array parameter?
>
Yes.
All other "options" are actual *cookie attribute* names, as defined by
the various IETF RFCs, while "lifetime" is just a convenient name used
by PHP. It doesn't correspond to a particular attribute, but instead
the values for the Expires and Max-Age attributes are derived from it.
I believe during discussion I insisted that the parameter be called
"attributes", for this very reason.
On another note, I also wanted that pretty much any key/value pair to
be accepted instead of raising an error, for forward compatibility.
Unfortunately, neither of these 2 points I raised were addressed, but
it also looked like the author abandoned the RFC mid-vote as he agreed
that targeting 7.2 at the time wasn't a good idea, only he didn't
actually close the vote. So ... I'm not even sure of the status of
this RFC?
Cheers,
Andrey.