PATCH: Better cross-domain cookie detection [BR 66090]

Waldo Bastian bastian at kde.org
Sun Nov 30 14:01:48 GMT 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sun November 30 2003 02:40, Dawit A. wrote:
> Hi,
>
> The following patch is intended to address the malfunctioning of
> cross-domain cookie detection (BR# 66090) when the web pages contain
> IFRAMES or FRAMES.
>
> The patch seems to correctly catch cross-domain requests even for iframes,
> but I am still being prompted for cookies that I should not be. Waldo, any
> ideas ? Hmm... I guess I should make sure the meta-data is set, i.e. the
> crossDomain function works properly.

Ah, very nice, I had a quick look into this already. I also noticed that the 
cross-domain check needs to be done in the http slave, instead of the khtml 
part. Otherwise it will not work correctly in combination with redirections.

E.g. http://www.kde.org loads the image http://www.kde.org/ads/ad.server.com/
foo.png which redirects to http://ad.server.com/foo.png

Will play a bit with your patch.

Cheers,
Waldo
- -- 
bastian at kde.org -=|[ SUSE, The Linux Desktop Experts ]|=- bastian at suse.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE/yfhMN4pvrENfboIRAs0IAJ9Mn06NQ3xp9/DmAFjqA4JjRA3MJQCfUMbT
8CZUSTWK6zG+iTXiO8UyhDw=
=JWe+
-----END PGP SIGNATURE-----




More information about the kde-core-devel mailing list