[Webkit-unassigned] [Bug 86067] [BlackBerry] Possible to clobber httponly cookie.

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue Jun 5 05:06:25 PDT 2012


https://bugs.webkit.org/show_bug.cgi?id=86067





--- Comment #42 from jochen at chromium.org  2012-06-05 05:06:25 PST ---
(In reply to comment #41)
> (In reply to comment #40)
> > (In reply to comment #38)
> > > In my opinion, mac added this *.txt to make the old test *.php pass.
> > > Although I changed the test case, mac's result will be also the same as *.txt.
> > > So it is needed for mac all the same.
> > > Do you agree with me?
> > 
> > I'd hope that now that you use the cookies testing framework, the test passes on all platforms.
> 
> I think mac fails because its httpOnly cookies can be changed by JavaScript.

Ok, I manually verified this.

Note that the platform/mac suppression will also apply to other ports, so when you land this change, there will be some redness.

Anyway, can you comment on https://bugs.webkit.org/show_bug.cgi?id=87208 that the failure on mac is because of an actual bug in their cookie jar?

otherwise, the patch looks good

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list