Skip to content

Fix inverted redirect-taint check for COEP: credentialless - #1959

Merged
annevk merged 1 commit into
mainfrom
coep-credentialless-taint
Sep 21, 2026
Merged

annevk merged 1 commit into
mainfrom
coep-credentialless-taint

Conversation

@annevk

@annevk annevk commented Sep 20, 2026

Copy link
Copy Markdown
Member

The check was introduced in 0613515 as "request's tainted origin flag is not set" and converted in 5dc54a7 to "request does not have a redirect-tainted origin". The conversion to the redirect-taint tri-state in 1d9380b dropped the negation's meaning, making
"Cross-Origin-Embedder-Policy allows credentials" return true precisely when the request had been redirect-tainted, rather than when it had not.

Fixes #1958.

The check was introduced in 0613515 as "request's tainted origin flag is
not set" and converted in 5dc54a7 to "request does not have a
redirect-tainted origin". The conversion to the redirect-taint tri-state
in 1d9380b dropped the negation's meaning, making
"Cross-Origin-Embedder-Policy allows credentials" return true precisely
when the request had been redirect-tainted, rather than when it had not.

Fixes #1958.
@annevk annevk mentioned this pull request Sep 20, 2026
@annevk
annevk merged commit 357bd98 into main Sep 21, 2026
2 checks passed
@annevk
annevk deleted the coep-credentialless-taint branch September 21, 2026 06:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

COEP credentials/taint

1 participant