Commit b8bd8ae
committed
Response: setCookie() sends the Max-Age attribute
Adds Max-Age next to expires - Max-Age takes precedence over expires (RFC 6265)
and, unlike expires, does not depend on the client clock; expires is kept for
ancient clients. This is something setcookie()'s options array could not control.
A non-positive number of seconds clamps Max-Age to 0 (immediate deletion), so
deleteCookie() now performs a real deletion (a past time => Max-Age=0) instead
of setting a session cookie with an empty value.1 parent 0c528e0 commit b8bd8ae
2 files changed
Lines changed: 13 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
249 | 249 | | |
250 | 250 | | |
251 | 251 | | |
252 | | - | |
| 252 | + | |
| 253 | + | |
253 | 254 | | |
254 | | - | |
| 255 | + | |
255 | 256 | | |
256 | 257 | | |
257 | 258 | | |
| |||
273 | 274 | | |
274 | 275 | | |
275 | 276 | | |
276 | | - | |
| 277 | + | |
277 | 278 | | |
278 | 279 | | |
279 | 280 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | | - | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
79 | 86 | | |
80 | 87 | | |
81 | 88 | | |
| |||
0 commit comments