> (sorry early post sent before finished...)
No problem. It's easy to get carried away.
> if the set cookie header includes a domain entry, like the following line:
> Set-Cookie: id=123123; domain=www.domain.com;path=/
> the cookie header is not parsed correctly [...]
According to RFC 2109, the above cookie should be rejected, since it
doesn't start with a dot:
4.2.2 Set-cookie syntax
Domain=domain
Optional. The Domain attribute specifies the domain for which
the
cookie is valid. An explicitly specified domain must always
start
with a dot.
Could this be the problem?