w3c / webappsec-suborigins

Suborigins
https://w3c.github.io/webappsec-suborigins/
Other
25 stars 9 forks source link

Remove unsafe-cookies #75

Open annevk opened 6 years ago

annevk commented 6 years ago

This would be better controlled by a feature policy.

annevk commented 6 years ago

(This applies to unsafe-authentication too.)