From: eldeerburn@... Date: 2001-09-20T01:58:09+09:00 Subject: [ruby-talk:21400] Re: Suggestions for new CGI lib On Wednesday 19 September 2001 04:14, Yukihiro Matsumoto wrote: > Hi, > > In message "[ruby-talk:21379] Re: Suggestions for new CGI lib" > > on 01/09/19, "Christian Rishoej" writes: > |> Could you explain "for security and to be more flexible" bit more? > | > |I find it quite useful to be able to distinguish between GET, POST and > |COOKIE variables, and in particular, being able to determine where a > |certain veriable came from. > | > |I agree that it does not provide any improved security, as the client can > |is free to "engineer" the request anyways. > > I think I understand what you meant. You want them for special cases, > don't you? > > By the way, do we really need to merge cookies too? I feel like it's > a different name space. Actually, IMO, we should keep cookies separate. From a codemonkey pespective cookies are a (klunky) way to effect persistent state. We should probably find another way to do this, so as to avoid the technical and perceptual (from the end user pov) problems with cookies. The other main use of cookies is storing information on th end user's system for purposes of autologin, maintaining transsessional state, tracking user configurations and statisitics, etc. The problem here is that many users disable cookies. The result of this ranges from users foregoing certain coneniences or customizations to some really bad and misleading aggregate data. Reliance upon cookies is a trap. Basically, what I am saying is that cookies need to be treated as a separate issue from the other request formats. Post and get are similar but separate. In most cases the way the data is transmitted is of marginal, if any, importance relative to the content. In a few cases, however, post vs get -does- have some meaning, so they should be distinguishable if necessary, as by, say, a request.format object. Just thoughts of the moment uplifted from the darkness. Regards, Kent Starr elderburn@mindspring.com