3 ms·
For me it was the fact that it did not work without third party cookies.
by bobochan 14y ago
For me it was the fact that it did not work without third party cookies.
- markruanedawson 14y agoHi - you can add an exception just for clipboard.com, not for all sites, which is what I did.
- gwf 14y agoHere's the thing ... we don't actually need 3rd party cookies. However, in most browsers you need to have 3rd party cookies enabled in order to read client local storage (not a cookie!) within an iframe that's in a different domain. We so this to digitally sign the API calls so that malicious 3rd party sites can neither spoof nor read the shared secret used for the digital signature. So the irony is that we make our API calls digitally signed (more secure) but to do so from the context of a bookmarklet you have to enable 3rd party cookies because browsers bundle that switch to the capability that we really need (i.e., there is no "enable loading of cross domain iframes that can read client local storage securely" option because its unfortunately pairs with 3rd party cookies).