Re: [spec-reviews] Clear Site Data (#62)

In 2.1:
> If the value of the header’s data-type-list contains cookies or *, then all cookies which would be sent along with any request to the response’s url's host MUST be removed.

This seems to contradict 3.4.4. Namely, if subdomain.example.com sends the clear cookie header, 2.1 implies that a cookie for .example.com would be cleared (since it would have been sent to all subdomains). 

---
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/spec-reviews/issues/62#issuecomment-123838780

Received on Wednesday, 22 July 2015 19:36:45 UTC