Alex Rivera | Logout

Cross domain cookie access (or session)

Asked 2009-06-02T12:36:58.390
12

While I realise that this is usually related to cross site scripting attacks, what I'm wondering is how can a session remain valid throughout multiple subdomains belonging to a single domain (example: a user logging in only once, and being able to access both subdomain1.domain.com and subdomain2.domain.com with the same session). I guess I first need to understand how it works, but so far I haven't been able to find much that would be of any relevance.

But then again, maybe I wasn't asking the right question.

Thanks in advance :)

Edit
Report

2 Answers

0

You can set a cookie for a specific domain.

In php, the setCookie() method contains a parameter in which you can specify the top-level domain, so the cookie is valid for all subdomains. Based on your tags, I see you are working in asp.net. Probably this also exists for asp...

after a little search for asp:

try this:

Response.Cookies("CookieName").Domain = ".mydomain.com"

or read this

answered 2009-06-02T12:41:04.670
0
answered 2010-02-18T12:30:55.540

Your Answer