Re: [whatwg/fetch] COEP:credentialless and the HTTP cache. (#1253)

End user visits A, which loads unique subresources from B (e.g., images representing pages the user likes). Attacker C checks which subresources from B are in the end user's cache. NPK is relevant here as without it A and C would see the same. These subresources from B don't have to be guarded by credentials.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1253#issuecomment-894077549

Received on Friday, 6 August 2021 07:56:49 UTC