erlyaws / yaws

Yaws webserver
https://erlyaws.github.io
BSD 3-Clause "New" or "Revised" License
1.28k stars 267 forks source link

set-cookie version=1? #330

Closed leoliu closed 5 years ago

leoliu commented 6 years ago

Example of header set by yaws: Set-Cookie: __id__=; Version=1; Path=/; HttpOnly

version doesn't appear in https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie and based on https://stackoverflow.com/questions/29124177/recommended-set-cookie-version-used-by-web-servers-0-1-or-2 it seems it might do more harm than good. thoughts?