-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 31 Aug 2004, at 8:00 PM, Oleg Broytmann wrote: > On Tue, Aug 31, 2004 at 12:33:19PM -0500, Martin Maney wrote: > >> 3.3.6 only requires that cookies sent in the redirect be >> ignored when the redirect is to a "third-party host" > > I know it. What I don't know is why people think they can set cookie > that will be sent back to a third-party host... by whatever way - HTTP > redirect, HTML pull, javascript... AFAIK the cookie & the redirected-to-host were the same beast. Perhaps i messed up on the "path=" portion of the cookie :-( Thanks for all the help folks. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (Darwin) iD8DBQFBNXr5KJDmEytdZIcRAvqUAKCO6i5VJq73iWHsT+vnN8P+grgJOQCfTCE6 SezUvHaTCGiaQUThQKbsYQ8= =s9lQ -----END PGP SIGNATURE-----