Re: [VOTE] Same Site Cookie RFC
| From: | Andrey Andreev | Date: | Sun, 29 Jul 2018 12:26:52 +0000 |
| Subject: | Re: [VOTE] Same Site Cookie RFC | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-102979@lists.php.net to get a copy of this message | ||
Hi,
On Sun, Jul 29, 2018 at 7:22 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
>
> One thing regarding implementation.
> Since the internet RFC has only 2 values for "samesite", the parameter can
> be
> bool rather than string so that users can avoid "broken security by a typo".
> If "samesite" has more than 2 values, the INI handler can be changed so that
> it can
> handle both bool and string parameters.
>
The attribute has 2 possible values, but those are 2 different modes
of operation *when enabled*, not 2 states in total. It doesn't fit in
a boolean, and even if it did it wouldn't be forward-compatible that
way.
Cheers,
Andrey.