Skip to content

COEP credentials/taint #1958

Description

@koal44

#1229 introduced COEP: credentialless. The later cookie integration in #1807 appears to have inverted the original intent:

To check if Cross-Origin-Embedder-Policy allows credentials...

-4. If request's origin is same origin with request's current URL's origin and request's tainted origin flag is not set, then return true.
+5. If request's origin is same origin with request's current URL's origin and request's redirect-taint is not "same-origin", then return true.

I think "not" should be removed.

Activity

  1. annevk commented on Sep 20, 2026

    @annevk
    Member

    Thanks, created #1959.

    cc @bvandersloot-mozilla

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions