[Webkit-unassigned] [Bug 86067] [BlackBerry] Possible to clobber httponly cookie.

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue Jun 5 04:41:48 PDT 2012


https://bugs.webkit.org/show_bug.cgi?id=86067





--- Comment #41 from Jason <jason.liu at torchmobile.com.cn>  2012-06-05 04:41:48 PST ---
(In reply to comment #40)
> (In reply to comment #38)
> > In my opinion, mac added this *.txt to make the old test *.php pass.
> > Although I changed the test case, mac's result will be also the same as *.txt.
> > So it is needed for mac all the same.
> > Do you agree with me?
> 
> I'd hope that now that you use the cookies testing framework, the test passes on all platforms.

I think mac fails because its httpOnly cookies can be changed by JavaScript.

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list