In \Drupal\Core\Session\SessionConfiguration::getCookieDomain() we ensure that the cookie domain starts with a dot.
// To maximize compatibility and normalize the behavior across user
// agents, the cookie domain should start with a dot.
$cookie_domain = '.' . $host;
The same code is present in Drupal 8.0.x and in any branch after that.
This had come from #1005570: Document leading dot requirement for $cookie_domain in settings.php, and in Drupal 7, the comment in drupal_settings_initialize in bootstrap.inc was as follows:
Per RFC 2109, cookie domains must contain at least one dot other than the first.
A previous version of the comment in settings.php was:
Make sure to always start the $cookie_domain
with a leading dot, as per RFC 2109.This has been deprecated. RFC 2109 is from February 1997!
http://stackoverflow.com/questions/9618217/what-does-the-dot-prefix-in-the-cookie-domain-mean
For example, if the value of the Domain attribute is "example.com", the user agent will include the cookie in the Cookie header when making HTTP requests to example.com, www.example.com, and www.corp.example.com. (Note that a leading %x2E ("."), if present, is ignored even though that character is not permitted, but a trailing %x2E ("."), if present, will cause the user agent to ignore the attribute.)
Issue fork drupal-2504881
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #1
alexborsody commentedComment #2
alexborsody commentedComment #3
alexborsody commentedComment #4
alexborsody commentedComment #15
quietone commentedThe code referred to in the IS was removed Jan 2015 in #2347877: Move DrupalKernel::initializeCookieGlobals() into a SessionConfiguration service. Commit 9a6582b1.
Therefore, closing as outdated. If this is incorrect reopen the issue, by setting the status to 'Active', and add a comment explaining what still needs to be done.
Thanks!
Comment #16
malcomio commentedComment #17
malcomio commentedAlthough that specific code was removed, we still set a leading dot in the cookie domain, which is a potential security issue:
Comment #18
quietone commentedHi, Issues for Drupal core should be targeted to the 'main' branch, our primary development branch. Changes are made on the main branch first, and are then back ported as needed according to the Core change policies. The version the problem was discovered on should be stated in the issue summary Problem/Motivation section. Thanks.
Comment #19
malcomio commentedComment #20
avpadernoThe following code is present in Drupal 8.0.x, but also in the main branch, which means that the issue reported here is present on any Drupal 8+ version.
Comment #21
avpadernoComment #23
avpadernoComment #24
smustgrave commentedThe unit test failures seem related to the change.
Comment #25
ankurjindalThe merge request !15479 seems not working as expected.
But via ServiceProviderBase class & alter function, able to achieve the same.
Hope it helps!