in reply to Cookie not being set
IE6 with the default security setting (or anything above Low Secuity) will reject cookies from site without a P3P policy and P3P CPP headers.
If you do not have a P3P policy (an unapproved standard deemed necessary by our malevolent dictator in Redmond) for your site you should (or your users will experience the problem I stated above). You can readup on P3P at W3C. W3C also provides a P3P Validator
As a side note - do not store usernames and passwords in a cookie, this is a security hole (that has been experienced at some well-know sites :) ). You might want to setup a sessionid for that user and reference (and expire) that id
Ovid's excellent CGI programming course addresses cookies and security concerns
| Just me, the boy and these two monks, no questions asked. |
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Cookie not being set
by caedes (Pilgrim) on Jun 24, 2002 at 08:04 UTC | |
|
(joshua) 2Re: Cookie not being set
by joshua (Pilgrim) on Jun 24, 2002 at 04:44 UTC | |
by grep (Monsignor) on Jun 24, 2002 at 04:56 UTC | |
by Ovid (Cardinal) on Jun 24, 2002 at 05:22 UTC | |
by joshua (Pilgrim) on Jun 24, 2002 at 05:42 UTC |