From ae8fcedbc7694010490ac2b365b397e8e2e39b44 Mon Sep 17 00:00:00 2001 From: Ryan West Date: Mon, 18 Mar 2013 19:18:35 -0700 Subject: [PATCH] small documentation update to outline caveat with SESSION_COOKIE_DOMAIN --- docs/ref/settings.txt | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/docs/ref/settings.txt b/docs/ref/settings.txt index b8041a8a9b..2d24ccb441 100644 --- a/docs/ref/settings.txt +++ b/docs/ref/settings.txt @@ -2287,6 +2287,12 @@ The domain to use for session cookies. Set this to a string such as ``".example.com"`` (note the leading dot!) for cross-domain cookies, or use ``None`` for a standard domain cookie. +Be cautious when updating this setting on a production site. If you update +this setting to enable cross-domain cookies on a site that previously used +standard domain cookies, existing user cookies will be set to the old +domain. This may result in them being unable to log in as long as these cookies +persist. + .. setting:: SESSION_COOKIE_HTTPONLY SESSION_COOKIE_HTTPONLY