3 ms·
One big reason to me: cookie security Currently all buckets share a domain and therefore share cookies. I've seen attacks (search for cookie bomb + fallback ma
by Gasparila 7y ago
One big reason to me: cookie security
Currently all buckets share a domain and therefore share cookies. I've seen attacks (search for cookie bomb + fallback manifest) that leverage shared cookies to allow an attacker to exfiltrate data from other buckets
- notfed 7y agoCookies support URL path restrictions.
- nyuszika7h 7y agoThat doesn't prevent unauthorized reading of the cookies. The only way to properly prevent it is using a different domain/subdomain. https://developer.mozilla.org/en-US/docs/Web/API/document/cookie#Security https://developer.mozilla.org/en-US/docs/Web/API/document/co...