interpret.py: Removed the code which removes HTTP_COOKIE from the CGI environment. Student code can now access cookies. Note: This was previously a security risk because malicious code could steal IVLE cookies. Now that we have separate domain space for other users, the worst you can do is: a) Steal your own IVLE cookie. b) Steal other user's non-IVLE cookies (ie. other public cookies).
This makes all student code vulnerable to cookie theft, but that is simply a disclaimer (if you use cookies, your apps are vulnerable). It is not a security risk to IVLE itself.