DescriptionAdd 'OriginAccessEntry::matchDomain'.
We need to ignore protocol shifts when calculating the first party for
cookies, as we're otherwise breaking sites that embed secure login
forms into insecure pages. It's better to weaken the check than to force
those sites to put everything into plaintext.
BUG=534749
R=jochen@chromium.org
Review URL: https://codereview.chromium.org/1607433007
Cr-Commit-Position: refs/heads/master@{#370098}
(cherry picked from commit 2cd11de2ba88e31413b0a38649f039d41206470b)
Committed: https://chromium.googlesource.com/chromium/src/+/4257f95488b09fcc2a3ca15f1dd09ed04ffead6c
Patch Set 1 #
Messages
Total messages: 2 (1 generated)
|