Open Bug 1651119 (schemeful-samesite) Opened 2 years ago Updated 7 days ago

[meta] Enable cookie sameSite schemeful


(Core :: Networking: Cookies, task, P3)





(Reporter: baku, Unassigned)


(Depends on 5 open bugs, Blocks 1 open bug)


(Keywords: meta, Whiteboard: [necko-triaged])
"Modify SameSite’s implementation in the user agent to consider origins with different schemes as cross-site. Thus https://site.example and http://site.example would now be considered cross-site.
Part of this effort will be to update Incrementally Better Cookies to match the intended behavior."

The behavior of schemeful-samesite as found in Nightly seems to be different to what is described in

In particular, this part does not seem to hold:

This means that both secure and insecure origins will retain access to the same set of cookies. I.e., if a user visits http://site.example with http://site.example/image.jpg and the response sets a cookie then when that user visits https://site.example the request to https://site.example/image.jpg will still send that same cookie.

In Nightly, when a cookie is set from, when I visit I get the following warning:

Cookie “foo” has been treated as cross-site against “” because the scheme does not match.

