<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>cookie does not set path information and http status codes are wrong</title> 
  <pubDate>Fri, 10 Apr 2026 19:46:48 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/11550</link> 
  <atom:link rel="self" type="application/rss+xml" title="cookie does not set path information and http status codes are wrong" href="https://bugs.horde.org/ticket/11550/rss" /> 
  <description>cookie does not set path information and http status codes are wrong</description> 
 
   
   
  <item> 
   <title>The cookie path is not set for horde webmailer, so the cooki</title> 
   <description>The cookie path is not set for horde webmailer, so the cookies are sent to every part of the domain. This causes the abbility to steal my login for other users of the server.

Also on logout the cookie is not destroyed.

And Horde does not use HTTP properly as defined in RFC 2616.
I am not able to see if login was successfull because even on login failure there is sent a 200 OK response code.

i would like to see changes in horde 4.0.9</description> 
   <pubDate>Thu, 18 Oct 2012 12:00:55 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/11550#t73836</link> 
  </item> 
   
  <item> 
   <title>&gt; The cookie path is not set for horde webmailer, so the coo</title> 
   <description>&gt; The cookie path is not set for horde webmailer, so the cookies are 
&gt; sent to every part of the domain. This causes the abbility to steal 
&gt; my login for other users of the server.

Configure Horde correctly.

&gt; Also on logout the cookie is not destroyed.

Which cookie?

&gt; And Horde does not use HTTP properly as defined in RFC 2616.
&gt; I am not able to see if login was successfull because even on login 
&gt; failure there is sent a 200 OK response code.

Which is perfectly correct. The login page is not a REST service.</description> 
   <pubDate>Thu, 18 Oct 2012 13:07:50 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/11550#t73851</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
