Re: First-Party-Only Traffic WAS: Re: First-Party-Only cookies
Mike West <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAKXHy=cX0uCV7vES95wOue4JTuESZ0LEvjV8-9-LXOPTrqoBSg@mail.gmail.com> |
It's not entirely clear to me what you're asking for, but Entry Point Regulation might or might not be along the lines of what you're proposing: https://w3c.github.io/webappsec-epr/ -mike -mike On Thu, Jan 21, 2016 at 5:07 PM, Kevin Chadwick <[email protected]> wrote: > I apologise upfront as I haven't looked into the RFC properly at all. > > I wonder if this idea could be extended so that I can instruct client > side that all traffic should originate from the primary domain? > > Or is that pointless as TLS *should* guarantee this anyway. I guess it > could be stripped from plain text but wonder if it would still be of any > use? > > Thinking about it that already exists as the content origin policy > directive, correct? > > -- > > KISSIS - Keep It Simple So It's Securable > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security >