Skip to content

Why does setCookie resolve with an error when domain doesn't match the host? #541

@edjonesdev

Description

@edjonesdev

Hello! I've been debugging an issue that came up with one of our apps and have narrowed the issue down to tough-cookie's implementation of S5.3 step 6. The RFC states: If the canonicalized request-host does not domain-match the domain-attribute: Ignore the cookie entirely and abort these steps.. We have an endpoint we call that responds with cookies with a domain field that doesn't match our host URL and it's causing an error in our app. According to the wording of the RFC, shouldn't this cookie simply be ignored instead of throwing an error?

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions