Why Illegal cookies are send by Browser and received by web servers (rfc2109)?
- by Artyom
Hello,
According to RFC 2109 cookie's value can be either HTTP token or quoted string, and token can't include non-ASCII characters.
Cookie's RFC 2109: http://tools.ietf.org/html/rfc2109#page-3
HTTP's RFC 2068 token definition: http://tools.ietf.org/html/rfc2068#page-16
However I had found that Firefox browser (3.0.6) sends cookies with utf-8…