Re: HttpOnly

On Mar 18 2008, at 20:55, Jim Manico wrote:

> What about http://www.ietf.org/rfc/rfc2965 ?

That is exactly what Daniel was talking about -- a standards-track  
spec that never made it into real life.

I think this needs to be marked as historic.
I also think the actual practice should be documented, and httponly is  
starting to become a part of that actual practice.

Gruesse, Carsten

Received on Wednesday, 19 March 2008 08:36:42 UTC