#1229 introduced COEP: credentialless. The later cookie integration in #1807 appears to have inverted the original intent:
To check if Cross-Origin-Embedder-Policy allows credentials...
-4. If request's origin is same origin with request's current URL's origin and request's tainted origin flag is not set, then return true.
+5. If request's origin is same origin with request's current URL's origin and request's redirect-taint is not "same-origin", then return true.
I think "not" should be removed.
#1229 introduced
COEP: credentialless. The later cookie integration in #1807 appears to have inverted the original intent:I think "not" should be removed.