mirror of
https://github.com/django/django.git
synced 2025-10-24 14:16:09 +00:00
Fixed #28741 -- Removed unnecessary leading dot from cross-domain cookie examples.
This commit is contained in:
@@ -653,7 +653,7 @@ you'll be logged in as the attacker and might inadvertently enter your
|
||||
sensitive personal data (e.g. credit card info) into the attackers account.
|
||||
|
||||
Another possible attack would be if ``good.example.com`` sets its
|
||||
:setting:`SESSION_COOKIE_DOMAIN` to ``".example.com"`` which would cause
|
||||
:setting:`SESSION_COOKIE_DOMAIN` to ``"example.com"`` which would cause
|
||||
session cookies from that site to be sent to ``bad.example.com``.
|
||||
|
||||
Technical details
|
||||
|
||||
Reference in New Issue
Block a user