Re: [w3ctag/design-reviews] "credentialless" embedder policy. (#582)

BTW, if we are concerned about (2) above and want to prevent the iframe from potentially getting access to ambient same-origin state, we could certainly include credentiallessness as part of the storage partition key (for example).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/582#issuecomment-775048653

Received on Monday, 8 February 2021 10:40:27 UTC