> I've just added this paragraph: > > Finally, note that the COOKIE_* configuration variables *only* affect > Quixote's session cookie; if you set your own cookies using the > HTTPResponse.set_cookie() method, then the cookie sent to the client is > completely determined by that set_cookie() call. > > Clear 'nuff? Perfectly so. > Hmmm... those config variables probably should be called > SESSION_COOKIE_*. So many other things have changed in 0.5 that one > more won't hurt. Any dissenters? +1 Especially if you really don't want them used outside of the session mechanism. At least without knowing the risk you are taking. No dissent from me. --- Patrick K. O'Brien Orbtech