Re: First-Party-Only cookies
Martin Thomson <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAPLxc=UXSu32N1pksbngsx2McAfqnHUTKaTJb_K-H2SMyYeViw@mail.gmail.com> |
On Wed, Jan 20, 2016 at 3:45 AM, Mark Goodwin <[email protected]> wrote: > My questions: What are your opinions on the relative merits of the stricter > / more relaxed variants of this proposal? What are your opinions in > providing both mechanisms via an option? It would be good to know specifically what scenario caused the exception to be created. On face value, I agree with you: the exception doesn't seem to belong. GET might be unique in the sense that it is heavily used, but from the perspective of how credentials are used and the damage that might be caused, a complete separation is cleaner. More so, the exception is surprising.