Record that state lives in the URL or on the server, never in a cookie
CI / full-gate (push) Successful in 2s
Mirror / github-mirror (push) Successful in 3s

This commit was merged in pull request #122.
This commit is contained in:
2026-09-15 14:21:44 +02:00
parent 79cee25b66
commit 5f9d74ae4f
+6 -3
View File
@@ -447,9 +447,12 @@ one-time setup. A file-map or table row gets a clause, not a paragraph.
same rule in their own language. An unmapped Kratos id renders Kratos' own wording — map the id when same rule in their own language. An unmapped Kratos id renders Kratos' own wording — map the id when
it matters. **Held by the author, never by a test:** slightly different wording is often the right it matters. **Held by the author, never by a test:** slightly different wording is often the right
call, and a build-failing check takes that judgment away. call, and a build-failing check takes that judgment away.
- Use well formed, standard compliant, rich URIs. Prefer state in the URL over POSTing it, for - Use well formed, standard compliant, rich URIs. **State lives in the URL or on the server, never in
example on list pages with filters and pagination. Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not a cookie.** Prefer state in the URL over POSTing it, for example on list pages with filters and
`ids=x,y`. pagination. A message for the page a redirect lands on rides its query string — `info-msg`,
`warn-msg`, `error-msg` — since a fragment never reaches the server. A cookie carries only what
must be bound to the browser: the session (`plainpages_jwt`) and the CSRF token (`plainpages_csrf`).
Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not `ids=x,y`.
## Comments ## Comments