# Serving static assets using cookie-free domain

**URL:** <https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916>\
**Category:** Support\
**Created:** [April 10, 2019, 2:14am UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916 "2019-04-10T02:14:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![P16](https://avatars.discourse-cdn.com/v4/letter/p/b19c9b/32.png) [@P16](https://meta.discourse.org/u/P16)\
**Post date:** [April 10, 2019, 2:14am UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916/1 "2019-04-10T02:14:11Z")

</div>

When running a YSlow report, I get a suggestion to use cookie-free domains. It then lists the assets that are not cookie-free - which are mostly js and css. The cookies are adding to the page load time. I have the CDN set up (Google) along with SSL.

I could set up a storage bucket (under a subdomain) with all the static assets, but is there a more efficient/better way?

Thanks!

---

<div class="post-metadata">

**Author:** ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)\
**Post date:** [April 10, 2019, 2:21am UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916/2 "2019-04-10T02:21:05Z")

</div>

That report is giving an outdated advice, there is no need to serve static assets in cookie free domains when using HTTP 2.

YSlow last commit was over 5 years ago.

---

<div class="post-metadata">

**Author:** ![P16](https://avatars.discourse-cdn.com/v4/letter/p/b19c9b/32.png) [@P16](https://meta.discourse.org/u/P16)\
**Post date:** [April 10, 2019, 2:56am UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916/3 "2019-04-10T02:56:51Z")

</div>

Thanks for that @Falco!

---

<div class="post-metadata">

**Author:** ![P16](https://avatars.discourse-cdn.com/v4/letter/p/b19c9b/32.png) [@P16](https://meta.discourse.org/u/P16)\
**Post date:** [April 10, 2019, 3:58am UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916/4 "2019-04-10T03:58:47Z")

</div>

@Falco while we are on HTTP/2, do you know if Discourse uses [multiplexing connections](https://hpbn.co/http2/#request-and-response-multiplexing) and [server push](https://w3c.github.io/preload/#server-push-%28http/2%29) to serve assets?

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [April 10, 2019, 4:11am UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916/5 "2019-04-10T04:11:43Z")

</div>

This doubly does not matter because if you use a CDN the CDN domain will (or at least easily can be) cookieless.

---

<div class="post-metadata">

**Author:** ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)\
**Post date:** [April 10, 2019, 3:11pm UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916/6 "2019-04-10T15:11:15Z")

</div>

> [@P16](#):
>
> Discourse uses [multiplexing connections](https://hpbn.co/http2/#request-and-response-multiplexing)

Well, yes. I don’t see a way to use HTTP/2 and not do that. It’s the most important feature of the protocol!

> [@P16](#):
>
> [server push](https://w3c.github.io/preload/#server-push-%28http/2%29) to serve assets

I did write a plugin and a change to core to enable this. As it’s not available in nginx, you need to add another thing in the stack, be it a CDN with push (Fastly, Cloudflare) or a more modern reverse proxy (Caddy, H20).

But my benchmarks showed a negligible difference in the page render time, and if you add the fact that is isn’t cache aware (only H20 has a workaround on that) it’s pretty bad.

I’m hopeful that with the RFC 8297 this will be better as you won’t wait for all middleware to do their thing before returning with the homework for the user agent, but that RFC didn’t get much attention so far.

---

<div class="post-metadata">

**Author:** ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)\
**Post date:** [May 10, 2019, 3:11pm UTC](https://meta.discourse.org/t/serving-static-assets-using-cookie-free-domain/113916/7 "2019-05-10T15:11:38Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
