Re: [VOTE] Same Site Cookie RFC

From: Date: Sun, 29 Jul 2018 12:26:52 +0000
Subject: Re: [VOTE] Same Site Cookie RFC
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.internals 
Request: Send a blank email to internals+get-102979@lists.php.net to get a copy of this message
Hi, On Sun, Jul 29, 2018 at 7:22 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > > One thing regarding implementation. > Since the internet RFC has only 2 values for "samesite", the parameter can > be > bool rather than string so that users can avoid "broken security by a typo". > If "samesite" has more than 2 values, the INI handler can be changed so that > it can > handle both bool and string parameters. > The attribute has 2 possible values, but those are 2 different modes of operation *when enabled*, not 2 states in total. It doesn't fit in a boolean, and even if it did it wouldn't be forward-compatible that way. Cheers, Andrey.

« previous php.internals (#102979) next »