Hacker News new | past | comments | ask | show | jobs | submit login

How does this work with something like Disqus/Facebook comments or other third party embedded plugins? Iframes only?



It's an optional flag included in Set-Cookie, much like HttpOnly.

So, if you don't want to use it, you don't have to, and nothing will change.


Cool, makes sense, thanks!


They should use localStorage




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: