Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SameParty cookie attribute #595

Closed
cfredric opened this issue Jan 11, 2021 · 6 comments
Closed

SameParty cookie attribute #595

cfredric opened this issue Jan 11, 2021 · 6 comments
Assignees
Labels
Progress: blocked on dependency Paused while some other design review finishes up. Provenance: Privacy Sandbox Resolution: unsatisfied The TAG does not feel the design meets required quality standards Review type: CG early review An early review of general direction from a Community Group

Comments

@cfredric
Copy link

Hello TAG!

I'm requesting a TAG review of the proposed SameParty cookie attribute.

The SameParty cookie attribute provides web developers a means to annotate cookies that are allowed to be set or sent in same-party (where "party" is defined by the collection of domains within the same First-Party Set), cross-site contexts; and hence should not be subject to the obsoletion/restrictions planned/shipped for third-party cookies in major browsers. In addition, SameParty cookies are blocked in cross-party, cross-site contexts.

Further details:

  • I have reviewed the TAG's API Design Principles
  • The group where the incubation/design work on this is being done (or is intended to be done in the future): Plan to be discussed in conjunction with First-Party Sets in PrivacyCG
  • The group where standardization of this work is intended to be done ("unknown" if not known): IETF HTTP Working Group
  • This work is being funded by: Google

You should also know that…

This is related to First-Party Sets, which was previously reviewed and discussed here: #342.

We'd prefer the TAG provide feedback as:

💬 leave review feedback as a comment in this issue and @-notify [cfredric, krgovind]

@cfredric cfredric added Progress: untriaged Review type: CG early review An early review of general direction from a Community Group labels Jan 11, 2021
@plinss plinss added this to the 2021-01-25-F2F-Q'onoS milestone Jan 13, 2021
@torgo
Copy link
Member

torgo commented Jan 27, 2021

Hi folks - this is an interesting proposal. We are just picking it up at our virtual f2f this week and discussing. I note that it builds on First Party Sets, which we previously reviewed and found issues with, which were not resolved. Furthermore there seems to be lack of multi-implementer support for First Party Sets based on e.g. the Mozilla feedback. Therefore it feels to me like it's premature to build things on top of First Party Sets?

@krgovind
Copy link

@torgo Thank you for taking a look at this proposal! I'd like to point to support from Edge, and support to adopt in PrivacyCG from Safari. First-Party Sets is currently under discussion in PrivacyCG, and the SameParty cookie attribute was also discussed there. The result of the SameParty discussion is cfredric/sameparty/issues/2

My impression was that we had responded to the issues raised on #342, but perhaps we need to articulate that better back on that thread? Here is my enumeration of our response to the various issues:

@hadleybeeman hadleybeeman self-assigned this Feb 8, 2021
@torgo
Copy link
Member

torgo commented Feb 8, 2021

OK - we have had a more detailed discussion on the proposal today on our TAG call. We have some very strong concerns about the underlying first party sets proposal #342 which I think that discussion has unearthed. Hence we're going to move the discussion back there and re-open that issue. Also pinging @chrishtr.

@hober hober added Progress: blocked on dependency Paused while some other design review finishes up. and removed Progress: in progress labels May 12, 2021
@hober
Copy link
Contributor

hober commented May 12, 2021

Marking this as blocked on dependency for #342.

@torgo
Copy link
Member

torgo commented Sep 14, 2021

@cfredric we are just reviewing again at our virtual f2f. We still feel this is blocked on First Party Sets - a spec which is in active development in the Privacy CG. Is there any additional info on multi-implementer support?

@plinss plinss changed the title Design review of SameParty cookie attribute Nov 8, 2021
@plinss plinss modified the milestones: 2021-11-15-week, 2022-01-10-week, 2022-02-14-week Dec 12, 2021
@torgo torgo modified the milestones: 2022-05-23-week, 2022-06-06-week Jun 4, 2022
@rhiaro
Copy link
Contributor

rhiaro commented Jul 26, 2022

We are closing this due to the dependency on First Party Sets.

@rhiaro rhiaro closed this as completed Jul 26, 2022
@rhiaro rhiaro added the Resolution: unsatisfied The TAG does not feel the design meets required quality standards label Jul 26, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Progress: blocked on dependency Paused while some other design review finishes up. Provenance: Privacy Sandbox Resolution: unsatisfied The TAG does not feel the design meets required quality standards Review type: CG early review An early review of general direction from a Community Group
9 participants