Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAFyT70hVsSX30bHYk-gjdUyi_a9am40Jw6bQmqtEetyCGVLV+g@mail.gmail.com>
Date: Tue, 24 Jun 2025 17:41:10 +0900
From: grape mingijung <mingijung.grape@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: xdg-open bypassing SameSite=Strict

Hello,

Thank you again for your continued attention to this topic.

With respect to sending SameSite=Strict cookies in CLI-initiated
navigations, it seems that different browsers may take slightly different
approaches to this issue. Because of that, it’s hard to predict how things
will develop going forward.

My impression is that allowing SameSite=Strict cookies in CLI-initiated
navigations is unlikely to cause significant compatibility issues in
practice.

I’ll be following any updates with interest.

Best regards,
grape mingijung

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.