anush...@chromium.org, dylan...@chromium.org
https://github.com/explainers-by-googlers/csp-sandbox-allow-same-site-none-cookies
HTML Spec https://github.com/whatwg/html/pull/10915
Enable a frame to signal the browser to include SameSite=None cookies in first-party requests from sandboxed frames when third-party cookie (3PC) restrictions are active using the allow-same-site-none-cookies value.
Chromium > Blink > SecurityFeature > ContentSecurityPolicy
Search tagsallow-same-site-none-cookies
https://github.com/w3ctag/design-reviews/issues/1004
TAG review statusEarly Design Review Satisfied
N/A- No OT
N/A- No OT
Gecko: Positive
WebKit: No signal (we discussed this with them and got tentatively positive feedback)
Web developers: Positive (see public feedback, we also received a private signal of developer demand)
Other signals:
Does this intent deprecate or change behavior of existing APIs, such that it has potentially high risk for Android WebView-based applications?
No
Feature use visible in the experimental Chrome DevTools Protocol Monitor, Cookies (and the reasons why they are included/excluded) are generally debuggable via the Network panel.
Yes
N/A
“AllowSameSiteNoneCookiesInSandbox”
False
https://g-issues.chromium.org/u/0/issues/372894175
UMA histogram value to measure the usage of the new ThirdPartyCookieAllowMechanism
UKM log usage and aggregate by urls that are using the value
https://sandbox-allow-same-site-none-cookies-demo.glitch.me/
135
None
https://chromestatus.com/feature/5090336588955648
--
You received this message because you are subscribed to the Google Groups "blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to blink-dev+...@chromium.org.
To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/d0ddbd19-fd21-483f-8a10-6c1e8f1b5177n%40chromium.org.
To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/ae298e38-ee2a-48f0-a6be-f95c3fdbddf3n%40chromium.org.
To unsubscribe from this group and stop receiving emails from it, send an email to blink-dev+unsubscribe@chromium.org.