Skip to content
This repository was archived by the owner on Nov 4, 2024. It is now read-only.

Treat insecure __cfduid cookies as insecure#379

Open
keks wants to merge 1 commit into
mozilla:mainfrom
keks:fix/202
Open

Treat insecure __cfduid cookies as insecure#379
keks wants to merge 1 commit into
mozilla:mainfrom
keks:fix/202

Conversation

@keks

@keks keks commented Mar 14, 2019

Copy link
Copy Markdown

Currently, CloudFlare's insecure cookies are ignored.
This commit removes this special treatment.

Fixes #202.


Sorry for being obnoxious in discussions, don't want to burn anyone out. Here is the fix to the issue. Tests have been updated, not sure it's entirely correct. Maybe it belongs into the "insecure, but HSTS" category.

Currently, CloudFlare's insecure cookies are ignored.
This commit removes this special treatment.

Fixes mozilla#202.
@keks

keks commented Apr 15, 2019

Copy link
Copy Markdown
Author

Hey @floatingatoll do you think you could review and possible merge this? thanks!

@floatingatoll

floatingatoll commented Apr 15, 2019 via email

Copy link
Copy Markdown
Contributor

@keks

keks commented Apr 15, 2019

Copy link
Copy Markdown
Author

It seems she missed the notification.

Hey @april, I hope there's no bad blood between us - could you review this? Thanks!

@floatingatoll

floatingatoll commented Apr 15, 2019 via email

Copy link
Copy Markdown
Contributor

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove __cfduid exemption

2 participants