[wp-trac] [WordPress Trac] #20286: Allow direct use of top level domains in multisites

WordPress Trac wp-trac at lists.automattic.com
Fri Mar 23 12:31:01 UTC 2012


#20286: Allow direct use of top level domains in multisites
--------------------------+------------------------------
 Reporter:  mickylmartin  |       Owner:
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  Multisite     |     Version:  3.3.1
 Severity:  major         |  Resolution:
 Keywords:                |
--------------------------+------------------------------

Comment (by Ipstenu):

 > Now going into child site's dashboard requires you to re-login cause of
 cookie not being set for all child top level domains.

 That's actually a 'problem' with domain mapping plugins, and I'm 99% sure
 it's from cross-domain scripting protection (which is to say, it's a bad
 idea to inherently trust that foobar.com and bazzot.com are okay sharing
 cookies, and would be something nefarious sorts would abuse).

 I'd call it not a bug but a security feature.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/20286#comment:1>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list