Security/Cookies: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
(→‎Work in progress: same-site cookies are done)
(→‎Existing functionality: add network.cookie.thirdparty.nonsecureSessionOnly)
 
(One intermediate revision by the same user not shown)
Line 27: Line 27:
** https://dxr.mozilla.org/mozilla-central/rev/85cf2e720a8405c43eabc9b34cce381b66d25ef9/netwerk/cookie/nsCookieService.cpp#3794-3816
** https://dxr.mozilla.org/mozilla-central/rev/85cf2e720a8405c43eabc9b34cce381b66d25ef9/netwerk/cookie/nsCookieService.cpp#3794-3816
** not exposed anywhere
** not exposed anywhere
* <tt>network.cookie.thirdparty.nonsecureSessionOnly</tt>
** for those third-party cookies set over HTTP, only accept them for this session
** https://bugzilla.mozilla.org/show_bug.cgi?id=1160368
* per-site third-party cookie blocking
* per-site third-party cookie blocking
** https://wiki.mozilla.org/Privacy/Features/Per-Site_Third-Party_Cookie_Setting
** https://wiki.mozilla.org/Privacy/Features/Per-Site_Third-Party_Cookie_Setting
Line 69: Line 72:
*** https://code.google.com/p/chromium/issues/detail?id=546820
*** https://code.google.com/p/chromium/issues/detail?id=546820
*** https://groups.google.com/a/chromium.org/d/topic/blink-dev/g_igIzSue40/discussion</s>
*** https://groups.google.com/a/chromium.org/d/topic/blink-dev/g_igIzSue40/discussion</s>
** <s>cookie-prefixes: https://code.google.com/p/chromium/issues/detail?id=541511 and https://groups.google.com/a/chromium.org/d/topic/blink-dev/ueCrrgFX8J4/discussion</s>
** <s>cookie-prefixes:
*** https://code.google.com/p/chromium/issues/detail?id=541511
*** https://groups.google.com/a/chromium.org/d/topic/blink-dev/ueCrrgFX8J4/discussion</s>
** <s>same-site cookies: https://code.google.com/p/chromium/issues/detail?id=459154</s>
** <s>same-site cookies: https://code.google.com/p/chromium/issues/detail?id=459154</s>
* Prior work in Firefox: https://wiki.mozilla.org/SecurityEngineering/ThirdPartyCookies
* Prior work in Firefox: https://wiki.mozilla.org/SecurityEngineering/ThirdPartyCookies

Latest revision as of 08:52, 26 April 2018

Existing functionality

Further work

Specifications

Work in progress

Research