4 ms·
I'm not sure what you mean by this; WebKit Tracking Prevention doesn't break third-party login. Third-party login works by handing a token back to the first par
by eridius 7y ago
I'm not sure what you mean by this; WebKit Tracking Prevention doesn't break third-party login. Third-party login works by handing a token back to the first party, who then stores it directly and validates it on the backend. After the initial login with the third party, the third party isn't involved anywhere that the browser can see. And the initial login happens in a browser window that's navigated directly to the third party, making them the first party for the login form (and therefore able to access any saved login data from previous logins).
In fact, this WebKit Tracking Prevention Policy explicitly states that third-party login is implied consent for the third party to identify the user as having the same identity in these multiple places.
- geofft 7y agoTBH a browser prevents Medium from showing a Google iframe in the top-right corner with "Hi geofft, I know your name is geofft, please click the login button geofft," that would be delightful....
- saagarjha 7y agoI’m not quite sure about this, but I think Safari will prevent cross-site tracking in this case until you interact with the thing.
- the8472 7y agoYou can achieve that with firefox containers or - if you want a bigger hammer - first-party isolation.
- om2 7y agoIf you logged into Medium with that account, then Medium would know, and could tell the I frame. But if you didn’t, then the iframe shouldn’t know your user ID unless you click and allow access, at least in Safari.