This post originated from an RSS feed registered with Python Buzz
by Phillip Pearson.
Original Post: Cookie security (43things example)
Feed Title: Second p0st
Feed URL: http://www.myelin.co.nz/post/rss.xml
Feed Description: Tech notes and web hackery from the guy that brought you bzero, Python Community Server, the Blogging Ecosystem and the Internet Topic Exchange
Are you on this list? It seems that it works in Firefox but not in Internet Explorer.
I think Firefox sends all your cookies (well, all of my cookies) whenever it makes a request to a site, no matter whether it's a "first party request" or a "third party request". The image in the above paragraph was a "third party request", which IE blocks, because 43things doesn't have a P3P privacy policy. It seems that not having a P3P policy is actually a Good Thing, because it makes it harder for people to exploit your users, at least if they are using Internet Explorer.
I guess the way to block this would be to require some sort of security token on links that result in something changing. Ideally it would only work for POSTs as well, but the important thing is the security token, as someone could easily post a form with javascript inside an iframe.