Alex Rivera | Logout

What's your favorite cross domain cookie sharing approach?

Asked 2008-11-04T19:09:41.120
46

I see iframe/p3p trick is the most popular one around, but I personally don't like it because javascript + hidden fields + frame really make it look like a hack job. I've also come across a master-slave approach using web service to communicate (http://www.15seconds.com/issue/971108.htm) and it seems better because it's transparent to the user and it's robust against different browsers.

Is there any better approaches, and what are the pros and cons of each?

Edit
Report

1 Answer

0

We use cookie chaining, but it's not a good solution since it breaks when one of the domains doesn't work for the user (due to filtering / firewalls etc.). The newer techniques (including yours) only break when the "master" server that hands out the cookies / manages logins breaks.

Note that your return.asp can be abused to redirect to any site (see this for example).

answered 2009-01-02T05:52:53.783

Your Answer