[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

RE: Re: Cookies at XML Europe 2004 -- Call for Participation

  • To: <bob@w...>,"Rich Salz" <rsalz@d...>,"Elliotte Rusty Harold" <elharo@m...>
  • Subject: RE: Re: Cookies at XML Europe 2004 -- Call for Participation
  • From: "Joshua Allen" <joshuaa@m...>
  • Date: Mon, 5 Jan 2004 15:06:52 -0800
  • Cc: "Edd Dumbill" <edd@u...>,"David Kunkel" <DKunkel@i...>,"XML-DEV" <xml-dev@l...>
  • Thread-index: AcPT3IyXbjzRVWfbSvmrybSNbSP/OQAAuQsQ
  • Thread-topic: Re: Cookies at XML Europe 2004 -- Call for Participation

cookies in url
Your privacy argument is fairly bogus -- the cookie still gets sent on
the wire in the clear with every request.  In any case, there is a
difference between passing "private data" as state between client and
server on every request (which is bad whether done with cookies or URL)
and using a session token to match a client with server state, which is
what I described.  The latter is absolutely essential in any non-trivial
web application.  I'll admit that there are reasons you would prefer to
store a session token in a cookie rather than URL, but not for the
reasons you describe (referrers can be easily managed).  Embedding state
(especially transient state prone to expiration such as authentication)
makes it difficult to bookmark things, compare URIs, etc -- in short
violates REST.

> -----Original Message-----
> From: Bob Wyman [mailto:bob@w...]
> Sent: Monday, January 05, 2004 2:35 PM
> To: Joshua Allen; 'Rich Salz'; 'Elliotte Rusty Harold'
> Cc: 'Edd Dumbill'; 'David Kunkel'; 'XML-DEV'
> Subject: RE:  Re: Cookies at XML Europe 2004 -- Call for
> Participation
> 
> Joshua Allen wrote:
> > The login token stored in the cookie
> > can always be embedded in the URL path,
> 	One of the original motivations for doing cookies was to
> remove "state information" from the URL so that it wouldn't compromise
> privacy by showing up in referral string information. If you embed
> "cookies" in URL's you end up leaking private data between sites. This
> is not good.
> 	See www-talk archives for 1994 or so to see the discussions on
> "state management" (i.e. cookies).
> 
> 		bob wyman


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.