php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #71106 Unclear explanation of cookie-domain
Submitted: 2015-12-12 19:34 UTC Modified: 2015-12-18 19:40 UTC
From: david dot bruchmann at gmail dot com Assigned: tpunt (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: david dot bruchmann at gmail dot com
New email:
PHP Version: OS:

 

 [2015-12-12 19:34 UTC] david dot bruchmann at gmail dot com
Description:
------------
The current documentation of cookie-domain on the page function.setcookie.php:

"
domain
The domain that the cookie is available to. Setting the domain to 'www.example.com' will make the cookie available in the www subdomain and higher subdomains. Cookies available to a lower domain, such as 'example.com' will be available to higher subdomains, such as 'www.example.com'. Older browsers still implementing the deprecated » RFC 2109 may require a leading . to match all subdomains.
"

This is unclear, the words higher and lower are used wrong or at least confusing and the explanation never helps much in practical usage.

I propose the following text:
"
domain
The cookie-domain can be set to widen the default restriction to the current domain. The main-domain and all sub-domains are covered if the cookie-domain is set to the main-domain such as 'example.com'. If the cookie-domain is set to a sub-domain such as 'sub1.example.com' then this and all sub-domains of 'sub1.example.com' are covered, i.e. 'sub2.sub1.example.com'.
Using the cookie-domain can be done from any of the covered domains and cookies are available on all these domains then. Setting the cookie-domain from a domain that is not covered by the defined domain is not possible.
Older browsers still implementing the deprecated » RFC 2109 may require a leading . to match all subdomains.
"


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2015-12-18 18:50 UTC] tpunt@php.net
Automatic comment from SVN on behalf of tpunt
Revision: http://svn.php.net/viewvc/?view=revision&revision=338304
Log: Fix doc bug #71106
 [2015-12-18 18:50 UTC] tpunt@php.net
-Assigned To: +Assigned To: tpunt
 [2015-12-18 18:53 UTC] tpunt@php.net
I'm not really keen on the the term "main-domain" you've used, and your description could probably be shortened too.

Here's my attempt to rephrase the description: https://svn.php.net/viewvc?view=revision&revision=338304

Please let me know if something is not clear in it.
 [2015-12-18 18:54 UTC] tpunt@php.net
-Status: Assigned +Status: Closed
 [2015-12-18 19:40 UTC] david dot bruchmann at gmail dot com
Yes the new explanation is better.
I see 2 problems with the item in general, these are special cases, so they never belong in a short explanation like here.
1) the domaine www.domain.com often is mapped to domain.com (or contrary) So www as subdomain is a special case.
2) cookies on the domain domain.com are not available in safari-browser but only the subdomains of it.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 06:00:01 2026 UTC