Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:99935 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 67934 invoked from network); 19 Jul 2017 15:09:58 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 19 Jul 2017 15:09:58 -0000 Authentication-Results: pb1.pair.com header.from=f.bosch@genkgo.nl; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=f.bosch@genkgo.nl; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain genkgo.nl designates 46.21.156.38 as permitted sender) X-PHP-List-Original-Sender: f.bosch@genkgo.nl X-Host-Fingerprint: 46.21.156.38 mail.genkgo.net Received: from [46.21.156.38] ([46.21.156.38:48997] helo=mail.genkgo.net) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id D0/99-02884-4467F695 for ; Wed, 19 Jul 2017 11:09:57 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=genkgo.nl; s=x; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:MIME-Version:Date: Message-ID:From:References:Cc:To:Subject:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=+vIAkfe/W4moTgPDlMHsh//B2qC35SPPRJZjBRoSq4M=; b=HgzkPWwehOF7ZjmxSaduNPMims Nmq/A6lBIqv45bYtI8OzqJHo1lbXIkZPB1g6jQXNmukEWcONZhVOoQxd9NaxaT6OnunQY9LzlK0cM KpLc/kjpw0Kw4gCQYhNedXxYuJkKTNANF57HtIbuRwWobstCdO0zTz1HwnD3kh4FtaCRZUnXF4eCQ jr8Gn9CKPnXlZYVRaTX/Rs6ljk+Yg1zZs9aFf+/MtOP9v35w3g3RU8ryg1ln/blJ8P2YKAEgxEq73 WzlqX4ntdk1A0MjeVCLQvb1QfiDuwskVZtlAVFrWz52q4Ty/lOBCgTFOQmwmqi2uMwm9GzFz+dh5u MXs70VzA==; Received: from [188.213.225.106] (helo=[192.168.15.254]) by mail.genkgo.net with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from ) id 1dXqbp-00016K-H7; Wed, 19 Jul 2017 17:09:53 +0200 To: Andrey Andreev Cc: "internals@lists.php.net" References: <14052ebf-efea-cb43-39e0-bdc30e493ff3@genkgo.nl> <08f6d5f1-a7e7-90a3-1b6a-ac353498cef8@genkgo.nl> Message-ID: Date: Wed, 19 Jul 2017 17:09:53 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Content-Language: nl-NL X-Antivirus-Scanner: Clean mail though you should still use an Antivirus Subject: Re: [PHP-DEV] [RFC] samesite cookie implementation From: f.bosch@genkgo.nl (Frederik Bosch | Genkgo) Hi Andrey, Thanks for you remark. If I understand correctly, PHP was 4-5 years ahead of HttpOnly becoming an actual standard. What a leaders they were back then. Best, Frederik On 19-07-17 17:06, Andrey Andreev wrote: > Hi, > > Not realizing I was looking at EOL dates, I (unintentionally) provided > some wrong info yesterday: > > On Tue, Jul 18, 2017 at 5:13 PM, Andrey Andreev wrote: >> - HttpOnly was released with PHP 5.2.0 in January 2011 - just 3 months prior >> to IETF RFC 6265 (April 2011) becoming a standards track. > PHP 5.2 was of course released way back, in 2006. My apologies for that. > > Cheers, > Andrey.