4 ms·
huh? You were always able to share sub-domain cookies with top-level domain cookies no? Set-Cookie: name=value; domain=google.com
by bdcp 4y ago
huh? You were always able to share sub-domain cookies with top-level domain cookies no?
Set-Cookie: name=value; domain=google.com
- zuhsetaqi 4y agoSetting cookies doesn't allow using Browser APIs lie GEO-Location
- eknkc 4y agoCan you load, let's say maps.google.com/somepage in a hidden iframe and use postmessage to send location data if it already has access? Or do browsers force top level navigation for such permissions?
- amenghra 4y agoThere were probably covert ways to obtain the same information but it's now easier for Google to grab the information using regular APIs. It also means if app X and app Y on their own subdomains were previously using location APIs without any tricks, you are now effectively opting into both apps. Bottom line: technically it doesn't matter but it probably makes a difference in practice.
- eknkc 4y agoYeah it makes a lot of sense to do it this way, however it does not feel that nefarious when there were plausable workarounds anyway.
- amenghra 4y agoBrowser could implement finer grain permissions (i.e. only permit the API use for a given top level path regexp) but I bet most users won't bother fine tuning their grants.
- lloeki 4y agoWhat about other apis such as web notifications or webcam and mic access? With separate domains we could allow notifications for one (e.g calendar) and disallow for another (e.g mail) at the browser level. Seems like it would now be a blanket allow for all of google.com (with a toggle for each product setting, maybe?) which sounds like a very user hostile move. I guess it depends if one considers Google products to be separate apps or Google as a whole to be a "Web OS". (Also on the technical side there's not just google.com but also google.<2 letter country TLD>, which is even worse in terms of CORS, certs, or whatever. Would they get rid of that?)
- aembleton 4y agoGoogle Maps could have set your location in a cookie that is shared with google.com. Then search would have your location anyway when you next visit it.