Re: document.cookie and HTTPOnly

On Tue, 2 Dec 2008, Anne van Kesteren wrote:
> 
> http://www.whatwg.org/specs/web-apps/current-work/multipage/dom.html#dom-document-cookie 
> currently does not take HTTPOnly into account. There should at least be 
> a note there that the user agent may not always reveal all cookies the 
> Cookie header contains. Likewise, HTTPOnly cookies are not be 
> overwritten by script.

Done. Let me know if there's a reference I can use...

-- 
Ian Hickson               U+1047E                )\._.,--....,'``.    fL
http://ln.hixie.ch/       U+263A                /,   _.. \   _\  ;`._ ,.
Things that are impossible just take longer.   `._.-(,_..'--(,_..'`-.;.'

Received on Tuesday, 2 December 2008 10:10:01 UTC