Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upHarden against HTTP cookie-based attacks #7962
Open
Labels
Comments
|
Thanks for filing this! It would be super valuable to write WPT tests for each of these cases; 1, 2 and 3 should be relatively straightforward, while 4 is probably unrealistic to test across all browsers. |
|
Assigning @avadacatavra and myself to this. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This paper demonstrates several cookie-based attacks. Servo (and all browsers) needs to implement the hardening described in the paper on page 719. Specifically: