Re: First-Party-Only Traffic WAS: Re: First-Party-Only cookies

Mike West <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CAKXHy=cX0uCV7vES95wOue4JTuESZ0LEvjV8-9-LXOPTrqoBSg@mail.gmail.com>
It's not entirely clear to me what you're asking for, but Entry Point
Regulation might or might not be along the lines of what you're proposing:
https://w3c.github.io/webappsec-epr/

-mike

-mike

On Thu, Jan 21, 2016 at 5:07 PM, Kevin Chadwick <[email protected]> wrote:

> I apologise upfront as I haven't looked into the RFC properly at all.
>
> I wonder if this idea could be extended so that I can instruct client
> side that all traffic should originate from the primary domain?
>
> Or is that pointless as TLS *should* guarantee this anyway. I guess it
> could be stripped from plain text but wonder if it would still be of any
> use?
>
> Thinking about it that already exists as the content origin policy
> directive, correct?
>
> --
>
> KISSIS - Keep It Simple So It's Securable
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.