when you’re “rolling your own” session management by using header(”Set-Cookie:… and you’re mixing temporary cookies with ones that have an expires= attribute, you may notice erratic behavior unless you set the temporary parameters first.

for example,

header(”Set-Cookie: permanent=important; expires=Sun, 17-Jan-2037 23:59:59 GMT”);
header(”Set-Cookie: temporary=trivial”);

may not work as expected, whereas if you switch the two around, you’re good to go.

i wonder if rfc-2109 mentions anything about this…

p.s. yes, i do prefer netscape’s standard for set-cookie syntax.