Skip to content

Change how Lax allowance computed (more RFC 2625bis compliance) - #3448

Closed
nikneym wants to merge 1 commit into
mainfrom
nikneym/cross-site-iframe-no-lax-exception-rfc-2625bis
Closed

nikneym wants to merge 1 commit into
mainfrom
nikneym/cross-site-iframe-no-lax-exception-rfc-2625bis

Conversation

@nikneym

@nikneym nikneym commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Specifically to distinguish cross-site iframe navigation from top-level navigation, this PR reworks how SameSite=Lax moved. Since we're not checking if its a navigation alone now, the field for it is also renamed to lax_allowed.

@nikneym
nikneym marked this pull request as draft September 8, 2026 12:34
@nikneym
nikneym force-pushed the nikneym/cross-site-iframe-no-lax-exception-rfc-2625bis branch from 38b6e35 to ceb2bdf Compare September 9, 2026 14:40
@nikneym
nikneym marked this pull request as ready for review September 9, 2026 14:43
@nikneym
nikneym force-pushed the nikneym/cross-site-iframe-no-lax-exception-rfc-2625bis branch 2 times, most recently from 89ef4d6 to 8bf7e3b Compare September 9, 2026 14:44
Specifically to distinguish cross-site iframe navigation from top-level navigation, this PR reworks how `SameSite=Lax` moved. Since we're not checking if its a navigation alone now, the field for it is also renamed to `lax_allowed`.
@nikneym
nikneym force-pushed the nikneym/cross-site-iframe-no-lax-exception-rfc-2625bis branch from 8bf7e3b to 380bdcf Compare September 9, 2026 16:46
@nikneym

nikneym commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Closing since fixed at #3335.

@nikneym nikneym closed this Sep 9, 2026
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 9, 2026
@nikneym
nikneym deleted the nikneym/cross-site-iframe-no-lax-exception-rfc-2625bis branch September 9, 2026 16:53
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant