Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Top-level sites and Clear-Site-Data #11

Closed
DCtheTall opened this issue Jun 7, 2021 · 0 comments
Closed

Top-level sites and Clear-Site-Data #11

DCtheTall opened this issue Jun 7, 2021 · 0 comments

Comments

@DCtheTall
Copy link
Collaborator

DCtheTall commented Jun 7, 2021

At the time of writing this, the explainer currently states that browsers give top-level sites the ability to clear third parties' cookies by sending a Clear-Site-Data header.

In other words, say example[1-10].com set cookies under toplevel.com's partition. Then toplevel.com could send a Clear-Site-Data header in a response which would clear all of example[1-10].com's cookies in the toplevel.com partition.

I am opening this issue because I am less convinced that this is functionality is either necessary or a good idea.

@annevk mentioned in the storage partitioning repo that this could allow malicious first parties to interfere with code running on third-party frames.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant