Open Bug 1161646 Opened 11 years ago Updated 3 years ago

Honor the "From Visited" third-party cookie blocking pref in prerendering

Categories

(Core :: DOM: Core & HTML, defect, P5)

defect

Tracking

()

People

(Reporter: ehsan.akhgari, Unassigned)

References

Details

We should make sure to not consider prerendered loads as visiting a domain for the first time as far as the "From visited" more of third-party cookie blocking is concerned. Without this, a malicious website would be able to prerender eviltracker.com without the user's knowledge, mark eviltracker.com's cookies as coming from an origin which we have visited from top-level navigation before, and enable iframes to eviltracker.com to start tracking users when embedded in third-party websites.
The implementation of third-party cookie blocking from visited is in bug https://bugzilla.mozilla.org/show_bug.cgi?id=730101. Also note, some users might disable third party cookies altogether. Not sure yet how we should deal with that case. The prerendered cookies ideally shouldn't get set until the user actually navigates to that page. But from talking to Ehsan, it sounds like that would be really tricky to implement. Perhaps not marking them first party would be enough to satisfy both options (from visited and blocked)? This would need more investigation.
(In reply to Tanvi Vyas [:tanvi] from comment #1) > The implementation of third-party cookie blocking from visited is in bug > https://bugzilla.mozilla.org/show_bug.cgi?id=730101. > Sorry, I linked the wrong bug. The right one is https://bugzilla.mozilla.org/show_bug.cgi?id=818340
Depends on: 818340
https://bugzilla.mozilla.org/show_bug.cgi?id=1472046 Move all DOM bugs that haven't been updated in more than 3 years and has no one currently assigned to P5. If you have questions, please contact :mdaly.
Priority: -- → P5
Component: DOM → DOM: Core & HTML
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.