privacycg / CHIPS

A proposal for a cookie attribute to partition cross-site cookies by top-level site
Other
116 stars 29 forks source link

Add section on (lack of) interaction with Storage Access API permissions. #42

Closed cfredric closed 2 years ago

cfredric commented 2 years ago

There's no privacy benefit that would come from blocking access to partitioned cookies when the Storage Access API permission has been refused or dismissed, and having access to partitioned cookies would be consistent with the existing access to partitioned storage on the device in such a scenario. So partitioned cookies should always be accessible, even if a Storage Access API prompt was previously rejected or dismissed.