The few corrupt cookies I’ve seen so far have all been variations of: Greetz to M, st0n3d, Jorgee, CoLdZeRo, and Tomato lol! which would seem to be hack attacks on cookies. I don’t know of a way to overwrite “other” site cookies from the web, so it probably implies the respective users have got viruses. I’m still inclined to think that it would be good to ignore invalid cookies without throwing an error because they could be generated by crashes, etc.
Cheers! Tony Pollard Another Dimension > On 15 Jul 2015, at 4:07 pm, Tony Pollard <[email protected]> wrote: > > Hmmm, interesting. I’ve used the (Mac) Paw app to simulate sending some > corrupt cookies to A4D (v6.1r13). Various combinations of no =, null and > otherwise Bad Cookies didn’t generate any errors. However, if I create a > cookie with a space instead of an = then I get the "[error] server: missing > '=' in cookie” 400 error (as you would expect). I’ve created a log trap in > On Web Connection to see if I can catch one of them. > > Many thanks, > > Tony Pollard > Another Dimension > > > On 14 Jul 2015, at 6:55 pm, Aparajita Fishman <[email protected]> wrote: > >> >>> I am getting the error a few times a day which must be frustrating for the >>> respective users, so I’m inclined to handle it. I could: >>> 1. Trap the error in a custom error page, look for a 400 status and clear >>> cookies there? >>> 2. Inspect the cookies before handing the request off to A4D? >>> Or is there a better way? >> >> The better way would be for me to be more lenient with invalid cookies. I'd >> like to see what their cookies are so I can know what to allow. >> >> Regards, >> >> Aparajita >> >> _______________________________________________ >> Active4D-dev mailing list >> [email protected] >> http://list.aparajitaworld.com/listinfo/active4d-dev >> Archives: http://active4d-nabble.aparajitaworld.com/ > > _______________________________________________ > Active4D-dev mailing list > [email protected] > http://list.aparajitaworld.com/listinfo/active4d-dev > Archives: http://active4d-nabble.aparajitaworld.com/ _______________________________________________ Active4D-dev mailing list [email protected] http://list.aparajitaworld.com/listinfo/active4d-dev Archives: http://active4d-nabble.aparajitaworld.com/
