Re: [RFC] samesite cookie implementation
| From: | lists@rhsoft.net | Date: | Tue, 18 Jul 2017 14:09:37 +0000 |
| Subject: | Re: [RFC] samesite cookie implementation | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-99901@lists.php.net to get a copy of this message | ||
Am 18.07.2017 um 16:00 schrieb Marco Pivetta:
On Tue, Jul 18, 2017 at 3:50 PM, lists@rhsoft.net <mailto:lists@rhsoft.net> <lists@rhsoft.net <mailto:lists@rhsoft.net>> wrote:how can they than be more security-sensitive within the encryption layer.... but that's not the point: setcookie() even with all it's params is easy and clear to use fopr anybody which has a clue what he is doing and there is no need to deprecated it nor design a new shiny API for it as replacementi don't share your optinion, especially talking about 'should be deprecated' where i get the feeling some peoples hobby is deprecate working thingscomparing cookie params with encryption is hopefully just kiddingIt could be a "hello world" function - same stuff. Also, yes, cookies are as security-sensitive stuff as crypto, if not often more (since crypto is usually handled at webserver level, and direct usage of openssl is more "rare")