php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #71106 Unclear explanation of cookie-domain
Submitted: 2015-12-12 19:34 UTC Modified: 2015-12-18 19:40 UTC
From: david dot bruchmann at gmail dot com Assigned: tpunt (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: david dot bruchmann at gmail dot com
New email:
PHP Version: OS:

 

 [2015-12-12 19:34 UTC] david dot bruchmann at gmail dot com
Description:
------------
The current documentation of cookie-domain on the page function.setcookie.php:

"
domain
The domain that the cookie is available to. Setting the domain to 'www.example.com' will make the cookie available in the www subdomain and higher subdomains. Cookies available to a lower domain, such as 'example.com' will be available to higher subdomains, such as 'www.example.com'. Older browsers still implementing the deprecated » RFC 2109 may require a leading . to match all subdomains.
"

This is unclear, the words higher and lower are used wrong or at least confusing and the explanation never helps much in practical usage.

I propose the following text:
"
domain
The cookie-domain can be set to widen the default restriction to the current domain. The main-domain and all sub-domains are covered if the cookie-domain is set to the main-domain such as 'example.com'. If the cookie-domain is set to a sub-domain such as 'sub1.example.com' then this and all sub-domains of 'sub1.example.com' are covered, i.e. 'sub2.sub1.example.com'.
Using the cookie-domain can be done from any of the covered domains and cookies are available on all these domains then. Setting the cookie-domain from a domain that is not covered by the defined domain is not possible.
Older browsers still implementing the deprecated » RFC 2109 may require a leading . to match all subdomains.
"


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2015-12-18 18:50 UTC] tpunt@php.net
Automatic comment from SVN on behalf of tpunt
Revision: http://svn.php.net/viewvc/?view=revision&revision=338304
Log: Fix doc bug #71106
 [2015-12-18 18:50 UTC] tpunt@php.net
-Assigned To: +Assigned To: tpunt
 [2015-12-18 18:53 UTC] tpunt@php.net
I'm not really keen on the the term "main-domain" you've used, and your description could probably be shortened too.

Here's my attempt to rephrase the description: https://svn.php.net/viewvc?view=revision&revision=338304

Please let me know if something is not clear in it.
 [2015-12-18 18:54 UTC] tpunt@php.net
-Status: Assigned +Status: Closed
 [2015-12-18 19:40 UTC] david dot bruchmann at gmail dot com
Yes the new explanation is better.
I see 2 problems with the item in general, these are special cases, so they never belong in a short explanation like here.
1) the domaine www.domain.com often is mapped to domain.com (or contrary) So www as subdomain is a special case.
2) cookies on the domain domain.com are not available in safari-browser but only the subdomains of it.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 04:00:02 2026 UTC