Skip to content

Fix cookie domain for qc.ca and other multi-label public suffixes - #4

Merged
simcamadd merged 1 commit into
masterfrom
fix/cookie-domain-public-suffixes
Oct 8, 2026
Merged

simcamadd merged 1 commit into
masterfrom
fix/cookie-domain-public-suffixes

Conversation

@simcamadd

@simcamadd simcamadd commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Context

Customer report on www.ithq.qc.ca: admin-ajax.php answered "Cookie set successfully" but the Set-Cookie header contained domain=qc.ca, a public suffix, so Chrome rejected the cookie (invalid Domain attribute). The composed TLD list only had gc.ca / gov.ca.

Changes

Only the $composedTlds list in getMainDomain() is changed:

  • Canadian provincial/territorial suffixes: ab.ca, bc.ca, mb.ca, nb.ca, nf.ca, nl.ca, ns.ca, nt.ca, nu.ca, on.ca, pe.ca, qc.ca, sk.ca, yk.ca.
  • Other common multi-label public suffixes (NZ, IL, TW, TH, ID, PH, VN, PK, CO, PE, UY, CL, VE, EC, PL, AT, BE, PT, GR, RO, HU, CY, MT, UA, AE, SA, EG, MA, TN, NG, KE, extra UK/IN).

All added entries were checked against the official Public Suffix List.

Testing

Plugin handler run on PHP 5.6 and 8.3 (Docker, stubbed WordPress), reading the actual Set-Cookie header:

  • www.ithq.qc.ca → domain=ithq.qc.ca (was qc.ca)
  • www.example.com.co → domain=example.com.co (was com.co)
  • www.example.fr, shop.example.co.uk → unchanged
  • php -l OK

Follow-ups (not in this PR)

  • PHP and Node.js examples in the public documentation contain the same suffix list and need the same update.

@simcamadd
simcamadd force-pushed the fix/cookie-domain-public-suffixes branch from 288cff7 to 30bcd67 Compare October 8, 2026 07:51
@simcamadd
simcamadd requested a review from a team October 8, 2026 07:53
getMainDomain() did not know provincial Canadian suffixes, so for
www.ithq.qc.ca the cookie was set with domain=qc.ca and rejected by
browsers. Add Canadian provinces/territories and other common
multi-label public suffixes.
@simcamadd
simcamadd force-pushed the fix/cookie-domain-public-suffixes branch from 30bcd67 to 165520e Compare October 8, 2026 07:56
@simcamadd
simcamadd removed the request for review from a team October 8, 2026 07:59
@simcamadd
simcamadd merged commit 0626f0b into master Oct 8, 2026
5 checks passed
@simcamadd
simcamadd deleted the fix/cookie-domain-public-suffixes branch October 8, 2026 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants