Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] Frames/cookies question

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] Frames/cookies question


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [Shib-Dev] Frames/cookies question
  • Date: Mon, 7 Dec 2009 14:11:57 -0500
  • Organization: The Ohio State University

Paul Hethmon wrote on 2009-12-07:
>> By definition, if we're saying that we can loophole the cookie
limitations
>> in frames using Javascript, then any of the client justifications for
>> blocking the cookies with the frame would apply to Javascript.
>
> Agreed. Though its tempting to try and exploit this loophole.

Apparently, yeah. But should we seriously consider shipping a logout or
discovery design that depends on it? What happens if it changes in FF 4.0?

I'd feel a lot better if I could find a clear justification for this
difference in constraints in a Mozilla design document, but I guess the next
step is ask somebody.

Obviously Safari, Chrome, and Opera to a lesser extent, also matter, but all
I need is one counterexample.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page