Re: First-Party-Only cookies
Martin Thomson <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAPLxc=X_pXF+6WDHVU=sA8ssiHuyBT++3y2zqGS6QdC9beaFzQ@mail.gmail.com> |
On Sat, Jan 23, 2016 at 1:33 AM, Mike West <[email protected]> wrote: > Excluding GET would make that more difficult, but would certainly improve > security. That's basically why I'm now leaning towards something like > `SameSite=Lax`, which would allow a stepwise improvement in CSRF protection > over time. I can tolerate that. While the patient is on the table, why not define both labels. SameSite=Unsafe/All perhaps?