Email or username:

Password:

Forgot your password?
Top-level
Melaskia

@simon Well, a very stupid summary with some elements of wrong.
1st party cookies with controlled subdomain and permissions will be fine.
The rest, notably 3rd party cookies are going to be very difficult (especially for FF and Safari since Chrome has kinda given up).

2 comments
Simon Willison

@Melaskia I’ll be honest: I don’t even completely understand what the term “third party cookie” means at the level of sending set-cookie headers!

Melaskia

@simon A first party cookie is when the website sends a cookie for its corresponding domain.
A Third party cookie is when you have a library (like GA) trying to set up a cookie on a separate domain.
Third party cookie will usually last until the active session of the browser or some expiry time deciding by the browser.

Go Up