First-Party-Only cookies

Mark Goodwin <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CAGXeGt+OQriyV4k6xQiepZZK3SZk9REJDh9HLuJ6ZSypO8sPEg@mail.gmail.com>
As you know, Mike West has been poking around at First-Party-Cookies (
https://tools.ietf.org/html/draft-west-first-party-cookies-04).  My main
reservation with his version of this idea is the relaxation of the rules
for 'safe' HTTP methods.

It turns out, others share my views on this. Because of this, Mike's open
to persuasion - that said, removing the safe methods exception makes
implementation harder for some sites (github have been playing with
First-Party-Only cookies for a while and like Mike's currently specified
semantics).

My questions: What are your opinions on the relative merits of the stricter
/ more relaxed variants of this proposal? What are your opinions in
providing both mechanisms via an option?

Thanks
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.