From da1a2d1ac8d49e519cfa5928689fd313f4ba71d7 Mon Sep 17 00:00:00 2001 From: Daniel Stenberg Date: Thu, 6 Oct 2016 09:40:47 +0200 Subject: TODO: Leave secure cookies alone --- docs/TODO | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'docs') diff --git a/docs/TODO b/docs/TODO index 1695d559c..24bbcd208 100644 --- a/docs/TODO +++ b/docs/TODO @@ -69,6 +69,7 @@ 5.7 Brotli compression 5.8 QUIC 5.9 Add easy argument to formpost functions + 5.10 Leave secure cookies alone 6. TELNET 6.1 ditch stdin @@ -554,6 +555,14 @@ This is not detailed in any FTP specification. deprecating the old ones. Allows better error messages and is generally good API hygiene. +5.10 Leave secure cookies alone + + Non-secure origins (HTTP sites) should not be allowed to set or modify + cookies with the 'secure' property: + + https://tools.ietf.org/html/draft-ietf-httpbis-cookie-alone-01 + + 6. TELNET 6.1 ditch stdin -- cgit v1.2.1