in reply to cookies, cgi::cookie, set by domain

Eureka_sg has the right answer; you cannot do this. Given a host name such as www.mydomain.co.uk, you can set and retrieve cookies for mydomain.co.uk and www2.mydomain.co.uk but you cannot do it for www.anotherdomain.co.uk, or co.uk, etc. In other words, given a domain name of N elements, you can set/get cookies for which the 1st element varies, but none of the others. This is obviously for security reasons because cookies are private transactions between a site and you, and to be able to put cookies for another site while delivering a page opens up a whole new world for potental misuse.

(Of course, it should be noted that nasty bugs were found in Netscape because their cookie validation service assumed that all domain names were 3 parts, thus making the case above of valid cookies in www.anotherdomain.co.uk work. This was quickly squashed once discovered).


Dr. Michael K. Neylon - mneylon-pm@masemware.com || "You've left the lens cap of your mind on again, Pinky" - The Brain
  • Comment on Re: cookies, cgi::cookie, set by domain