But is there news on how we might roll out 0.6 (upgrade from 0.5.1) without being able to have users remove cookies?
Perhaps relatedly, we do want to change our 'des_key' but am unsure if that is safe to do. Also 'session_domain' which we seem to have in production as '' (NULL)
p.s. When I put the new version into place (at the existing URL) it breaks logged sessions, logging this:
roundcube: Session authentication failed for . . invalid auth cookie sent
This is even if I leave des_key and session_domain exactly as they were.
Ben