cookie Max-Age should be set to -1 when invalidating the cookie#19
cookie Max-Age should be set to -1 when invalidating the cookie#19renerocksai merged 2 commits intozigzap:masterfrom
Conversation
|
According to the Mozilla doc:
Based on that information, I see no benefit in changing According to this springio doc here:
An expired cookie (max-age: 0) will be removed when the browser closes, too. This is why we use max-age: 0 to implement session cookies. Which is also reflected / recommended in the facil.io docs docs:
So, basically, 0 and -1 have the same effects, according to the above docs. |
|
Thanks for the work you put into it. It's just that I don't see a reason to change one arbitrary constant to another if they're supposed to lead to identical consequences. If, however, you can show me evidence that there seems to be deviating behavior by popular browsers, it might be a good idea to cater to their needs so users of Zap don't have to. |
|
Setting to 0 will set it to session. It won't expire. |
|
Btw session usually means when it will be cleaned up when browser closes so it's a slight annoyance. Because the value is already set to invalid so it doesn't leak much information except that the cookie is in the browser cache. I personally prefer the cookie to be removed by the browser which is what happens when it's set to -1. |
|
Btw all this is observed in chrome. |
|
So, to be clear, for the record, let's state it how it supposedly is:
So this statement from MDN is wrong:
And this statement from spring.io is wrong:
Because according to you, on a negative value the browser won't wait until it is closed to remove the cookie. Man, the web is a mess. I will trust you on this one and merge. |
Browser will delete the cookie automatically when the max-age is set to -1.