9 ms·
This is a very positive change, but I'd be interested to know how the Mozilla folks think about 'collateral damage' from a policy point of view. The exceptions
by Joe8Bit 6y ago
This is a very positive change, but I'd be interested to know how the Mozilla folks think about 'collateral damage' from a policy point of view.
The exceptions and shared state lead me to believe they've thought about it and tried to mitigate it as much as possible, but how much is acceptable? If this breaks more than they thought it would, is it something they'd be comfortable rolling back or changing?
For example, if I read this post correctly, this change would put a hard upper limit in SSO logins to 30 days for Firefox users (because StorageAccess is only granted for 30 days). That might not be a _huge_ issue for most people, but it'll add a hard limit to something that's never had a browser enforced hard limit before.
- Chilinot 6y agoI guess the SSO token will still be valid, just not usable for SSO purposes after those 30 days. And most likely you will just have to click "Accept" again on the cookie popup to get it working as before for another 30 days. However, dont basically all SSO cookies live far shorter than 30 days? To my knowledge all SSO services i have used have expired earlier requiring me to log back in again.
- stickfigure 6y ago> However, dont basically all SSO cookies live far shorter than 30 days? At least in the case of Google auth: While G may reauthenticate you every 30 days, it's global to your web browser. So after you have reauthenticated, you are back to "logged in" to websites you've logged in to with Google. In the "old way" you only need to reauthenticate to Google, Microsoft, etc once a month. With this new Firefox UX, you still need to reauthenticate to Google, Microsoft, etc once a month, but you also need to click "OK Keep StorageAccess granted" once a month for every website that you use federated login on. There are few auth providers but many more auth consumers.
- mxxx 6y agoThe 30 day limit is access to the storage API. So presumably the data is still there, you just need to give permission for it to be accessed again. It doesn’t necessarily imply that it just logs you out on 30 days by emptying the state.
- pyentropy 6y agoJust do a redirect with session as a query parameter (like many OAuth apps do it anyway). Each site can then persist the user session for more than a month.
- Ayesh 6y agoI think cookies have a limit too. It may be not from the spec, but I never saw a single cookie in my Firefox that's longer than a year.