•  
      request #19302 Force Chromium-based browsers to segment the cache to defend against cache probing
    Infos
    #19302
    Thomas Gerbet (tgerbet)
    2021-02-18 16:14
    2021-02-12 15:52
    20873
    Details
    Force Chromium-based browsers to segment the cache to defend against cache probing

    We should instruct browsers supporting the Fetch Metadata Request Headers (Chromium-based browsers only at this time) to segment their cache according to the origin of the requests in order to defend against a class of cross-site leaks. While Firefox does not support the Fetch Metadata Request Headers since FF85 the cache is partitioned by top-level origin.

    References:

    Other
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2021-02-18
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Integrated into Tuleap 12.5.99.140

    • Status changed from Under review to Closed
    • Connected artifacts
    • Close date set to 2021-02-18
    User avatar
    Thomas Gerbet (tgerbet)2021-02-12 16:02

    • Summary
      -Force Chromium-based browsers to segment the cache to to defend against cache probing 
      +Force Chromium-based browsers to segment the cache to defend against cache probing 
    • Status changed from Under implementation to Under review
    User avatar
    Thomas Gerbet (tgerbet)2021-02-12 15:53
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes