Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

request_headers may send SameSite cookies cross-site #111

Open
chlily1 opened this issue Apr 9, 2019 · 2 comments
Open

request_headers may send SameSite cookies cross-site #111

chlily1 opened this issue Apr 9, 2019 · 2 comments

Comments

@chlily1
Copy link

chlily1 commented Apr 9, 2019

If a NEL policy requests Cookie headers be sent in the request_headers report field, then SameSite cookies may be sent cross-site to a report collector.

@clelland
Copy link
Contributor

Discussed at TPAC, and the sentiment in the room was that we perhaps should simply not send cookies in reports.
(Also see #112)

@yoavweiss
Copy link
Contributor

Beyond that, NEL collectors in the room are currently actively stripping that information and have no use-case for it. So there's no apparent trade-off in simply removing headers from the reports.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants