-
Notifications
You must be signed in to change notification settings - Fork 151
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Introduce "Schemeful Same-Site" cookies. #1324
Conversation
Can you please review, @chlily1? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A few small comments. Also, please add a changelog entry.
draft-ietf-httpbis-rfc6265bis.md
Outdated
|
||
For a given request ("request"), the following algorithm returns `same-site` or | ||
`cross-site`: | ||
1. If A and B are both scheme/host/port triples: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we use the same "tuple origin" terminology as HTML here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi Mike,
Has there been any changes on the IETF/WHATWG term differences? This same point came up during the PR into cookie inc. mikewest/cookie-incrementalism#3 (comment)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the review comments! I'm going to let this bake for a few days (and let some folks respond), and eat a lot of pumpkin pie in the meantime. Looking to pick it up early next week. |
I'd suggest that we try to get this landed, and then spin off a new -07. WDYT? |
SGTM! My goal is to address feedback before EOW (and I'll file a new follow-up issue to hash out origin vs tuple and we can make changes the next go around): filed #1337 |
a71e172
to
e783050
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I can't seem to comment on the line but 654 isn't correct any longer.
Great catch, let me fix that up. |
Thanks for punting the terminology conversation out to a separate bug. LGTM2; I'll land this and spin out an -07 draft. |
Thanks all! |
Opening for discussion, per the last interim group meeting.
This should correspond to https://tools.ietf.org/html/draft-west-cookie-incrementalism-01#section-3.3