HTTPOnly cookie support in Firefox... - brad's life — LiveJournal
Brad Fitzpatrick

HTTPOnly cookie support in Firefox... [Sep. 5th, 2007|09:09 pm]
Brad Fitzpatrick
Five Fucking Years

About time. And a bit longer than Ten Fucking Days.

Danga sponsored development of this patch (twice?) many years ago. Glad to see it finalllly go in.

From: msirub
2007-09-06 04:27 am (UTC)
[User Picture]From: burr86
2007-09-06 04:57 am (UTC)
From: franklinmint
2007-09-06 04:57 am (UTC)

have to admit...

...whiny blog posts drove me to investigate and revive that Six Apart patch.

FWIW, I just ignore all bureaucratic rejection messages, especially for security stuff. Six Apart should have done that, too. ;)
[User Picture]From: taral
2007-09-06 05:03 am (UTC)
I hate the people who say "it's not a perfect solution so we shouldn't do it."
[User Picture]From: pyesetz
2007-09-06 05:39 am (UTC)
Congratulations on Danga's completed project!  Coincidentally, 5 fucking years was how long it took me to get the governments of USA and Canada to allow me to move Northward.
[User Picture]From: mart
2007-09-06 06:08 am (UTC)

For what it's worth, Opera's 9.5 Alpha (released two days ago) apparently has support for it too.

[User Picture]From: scosol
2007-09-06 06:37 am (UTC)
i've been an opera user since the 6.x days-
and yeah- the 9.5 weekly seems to be kicking ass-
the pageloads are even faster and the imap support seems... robustified
[User Picture]From: scosol
2007-09-06 06:38 am (UTC)
i kinda agree with the 5-year timeframe ;) - in the sense that i see an XXS vulerability as strictly a server-side problem
[User Picture]From: codetoad
2007-09-06 07:41 am (UTC)
I thought Httponly was in FF but was flawed until now'ish?
[User Picture]From: avva
2007-09-08 08:42 pm (UTC)
