4 ms·
You'll find an answer in https://web.dev/same-site-same-origin/ https://web.dev/same-site-same-origin/: [...] for domains such as .co.jp or .github.io, just us
by jub0bs 6y ago
You'll find an answer in https://web.dev/same-site-same-origin/ https://web.dev/same-site-same-origin/:
[...] for domains such as .co.jp or .github.io, just using the TLD of .jp or .io is not granular enough to identify the "site". And there is no way to algorithmically determine the level of registrable domains for a particular TLD. That's why a list of "effective TLDs"(eTLDs) was created.
If foo.github.io and bar.github.io were considered same-site, one subdomain could mount cross-origin same-site attacks against the other. I'm guessing that's why companies that have multiple tenants on the same domain (github.io, in this case) ask that the domain be added to the public-suffix list: for isolation purposes. Other examples of public suffixes are azurewebsites.net (Azure App Services) and repl.co (Repl.it).