First-Party-Only cookies
Mark Goodwin <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAGXeGt+OQriyV4k6xQiepZZK3SZk9REJDh9HLuJ6ZSypO8sPEg@mail.gmail.com> |
As you know, Mike West has been poking around at First-Party-Cookies ( https://tools.ietf.org/html/draft-west-first-party-cookies-04). My main reservation with his version of this idea is the relaxation of the rules for 'safe' HTTP methods. It turns out, others share my views on this. Because of this, Mike's open to persuasion - that said, removing the safe methods exception makes implementation harder for some sites (github have been playing with First-Party-Only cookies for a while and like Mike's currently specified semantics). My questions: What are your opinions on the relative merits of the stricter / more relaxed variants of this proposal? What are your opinions in providing both mechanisms via an option? Thanks