Commit da1a2d1a authored by Daniel Stenberg's avatar Daniel Stenberg
Browse files

TODO: Leave secure cookies alone

parent c271b1c2
Loading
Loading
Loading
Loading
+9 −0
Original line number Diff line number Diff line
@@ -69,6 +69,7 @@
 5.7 Brotli compression
 5.8 QUIC
 5.9 Add easy argument to formpost functions
 5.10 Leave secure cookies alone

 6. TELNET
 6.1 ditch stdin
@@ -554,6 +555,14 @@ This is not detailed in any FTP specification.
 deprecating the old ones. Allows better error messages and is generally good
 API hygiene.

5.10 Leave secure cookies alone

 Non-secure origins (HTTP sites) should not be allowed to set or modify
 cookies with the 'secure' property:

 https://tools.ietf.org/html/draft-ietf-httpbis-cookie-alone-01


6. TELNET

6.1 ditch stdin