Comment on Cookie Bomb or Let's Break the InternetparentComments−gfodor12yYour idea would likely break any site on the internet that uses authentication and subdomins, isn't it clear why this isn't being considered?−zaroth12yOr sites could opt-in to this with a header?EDIT: homakov says the same thing down thread.−hrjet12yYes, it is backwards incompatible. Perhaps it could be enforced in HTTP 2?
Comments
Your idea would likely break any site on the internet that uses authentication and subdomins, isn't it clear why this isn't being considered?
Or sites could opt-in to this with a header?
EDIT: homakov says the same thing down thread.
Yes, it is backwards incompatible. Perhaps it could be enforced in HTTP 2?