In \Drupal\Core\Session\SessionConfiguration::getCookieDomain() we ensure that the cookie domain starts with a dot.

// To maximize compatibility and normalize the behavior across user
// agents, the cookie domain should start with a dot.
$cookie_domain = '.' . $host;

The same code is present in Drupal 8.0.x and in any branch after that.

This had come from #1005570: Document leading dot requirement for $cookie_domain in settings.php, and in Drupal 7, the comment in drupal_settings_initialize in bootstrap.inc was as follows:

Per RFC 2109, cookie domains must contain at least one dot other than the first.

A previous version of the comment in settings.php was:

Make sure to always start the $cookie_domain
  with a leading dot, as per RFC 2109.

This has been deprecated. RFC 2109 is from February 1997!

See RFC 6265 section 4.1.2.3

http://stackoverflow.com/questions/9618217/what-does-the-dot-prefix-in-the-cookie-domain-mean

For example, if the value of the Domain attribute is "example.com", the user agent will include the cookie in the Cookie header when making HTTP requests to example.com, www.example.com, and www.corp.example.com. (Note that a leading %x2E ("."), if present, is ignored even though that character is not permitted, but a trailing %x2E ("."), if present, will cause the user agent to ignore the attribute.)

Issue fork drupal-2504881

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

alexborsody’s picture

Issue summary: View changes
alexborsody’s picture

Issue summary: View changes
alexborsody’s picture

Issue summary: View changes
alexborsody’s picture

Issue summary: View changes

Version: 8.1.x-dev » 8.2.x-dev

Drupal 8.1.0-beta1 was released on March 2, 2016, which means new developments and disruptive changes should now be targeted against the 8.2.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.2.x-dev » 8.3.x-dev

Drupal 8.2.0-beta1 was released on August 3, 2016, which means new developments and disruptive changes should now be targeted against the 8.3.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.3.x-dev » 8.4.x-dev

Drupal 8.3.0-alpha1 will be released the week of January 30, 2017, which means new developments and disruptive changes should now be targeted against the 8.4.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.4.x-dev » 8.5.x-dev

Drupal 8.4.0-alpha1 will be released the week of July 31, 2017, which means new developments and disruptive changes should now be targeted against the 8.5.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.5.x-dev » 8.6.x-dev

Drupal 8.5.0-alpha1 will be released the week of January 17, 2018, which means new developments and disruptive changes should now be targeted against the 8.6.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.6.x-dev » 8.7.x-dev

Drupal 8.6.0-alpha1 will be released the week of July 16, 2018, which means new developments and disruptive changes should now be targeted against the 8.7.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.7.x-dev » 8.8.x-dev

Drupal 8.7.0-alpha1 will be released the week of March 11, 2019, which means new developments and disruptive changes should now be targeted against the 8.8.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.8.x-dev » 8.9.x-dev

Drupal 8.8.0-alpha1 will be released the week of October 14th, 2019, which means new developments and disruptive changes should now be targeted against the 8.9.x-dev branch. (Any changes to 8.9.x will also be committed to 9.0.x in preparation for Drupal 9’s release, but some changes like significant feature additions will be deferred to 9.1.x.). For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

Version: 8.9.x-dev » 9.1.x-dev

Drupal 8.9.0-beta1 was released on March 20, 2020. 8.9.x is the final, long-term support (LTS) minor release of Drupal 8, which means new developments and disruptive changes should now be targeted against the 9.1.x-dev branch. For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

Version: 9.1.x-dev » 9.2.x-dev

Drupal 9.1.0-alpha1 will be released the week of October 19, 2020, which means new developments and disruptive changes should now be targeted for the 9.2.x-dev branch. For more information see the Drupal 9 minor version schedule and the Allowed changes during the Drupal 9 release cycle.

quietone’s picture

The code referred to in the IS was removed Jan 2015 in #2347877: Move DrupalKernel::initializeCookieGlobals() into a SessionConfiguration service. Commit 9a6582b1.

Therefore, closing as outdated. If this is incorrect reopen the issue, by setting the status to 'Active', and add a comment explaining what still needs to be done.

Thanks!

malcomio’s picture

Version: 9.2.x-dev » 11.x-dev
Issue summary: View changes
Related issues: +#1005570: Document leading dot requirement for $cookie_domain in settings.php
malcomio’s picture

Status: Closed (outdated) » Active

Although that specific code was removed, we still set a leading dot in the cookie domain, which is a potential security issue:

If an attacker were able to exploit a vulnerability in the parent domain, or in any other subdomain of the parent, they would be able to steal the cookies and thus gain access to the website.

quietone’s picture

Version: 11.x-dev » main

Hi, Issues for Drupal core should be targeted to the 'main' branch, our primary development branch. Changes are made on the main branch first, and are then back ported as needed according to the Core change policies. The version the problem was discovered on should be stated in the issue summary Problem/Motivation section. Thanks.

malcomio’s picture

Title: Remove deprecated leading dot requirement from settings.php » Remove deprecated leading dot from cookie domain
avpaderno’s picture

The following code is present in Drupal 8.0.x, but also in the main branch, which means that the issue reported here is present on any Drupal 8+ version.

    // To maximize compatibility and normalize the behavior across user
    // agents, the cookie domain should start with a dot.
    $cookie_domain = '.' . $host;
avpaderno’s picture

Issue summary: View changes

avpaderno’s picture

Status: Active » Needs review
smustgrave’s picture

Status: Needs review » Needs work

The unit test failures seem related to the change.

ankurjindal’s picture

The merge request !15479 seems not working as expected.
But via ServiceProviderBase class & alter function, able to achieve the same.
Hope it helps!

sivaji_ganesh_jojodae made their first commit to this issue’s fork.