[wp-trac] [WordPress Trac] #20286: Allow direct use of top level domains in multisites
WordPress Trac
wp-trac at lists.automattic.com
Fri Mar 23 12:31:01 UTC 2012
#20286: Allow direct use of top level domains in multisites
--------------------------+------------------------------
Reporter: mickylmartin | Owner:
Type: defect (bug) | Status: new
Priority: normal | Milestone: Awaiting Review
Component: Multisite | Version: 3.3.1
Severity: major | Resolution:
Keywords: |
--------------------------+------------------------------
Comment (by Ipstenu):
> Now going into child site's dashboard requires you to re-login cause of
cookie not being set for all child top level domains.
That's actually a 'problem' with domain mapping plugins, and I'm 99% sure
it's from cross-domain scripting protection (which is to say, it's a bad
idea to inherently trust that foobar.com and bazzot.com are okay sharing
cookies, and would be something nefarious sorts would abuse).
I'd call it not a bug but a security feature.
--
Ticket URL: <http://core.trac.wordpress.org/ticket/20286#comment:1>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software
More information about the wp-trac
mailing list