Am 28.08.2014 03:24, schrieb Kevin W. Wall: > but just change it so that it uses domain cookies rather than site > cookies. NO! Please don't do that. OWASP tries to teach people security, and domain cookies are a insecure solution there. Achim