Bug 251094

Summary: The Clear-Site-Data HTTP header should obey origin partition
Product: WebKit Reporter: Chris Dumez <cdumez>
Component: WebKit2Assignee: Chris Dumez <cdumez>
Status: RESOLVED FIXED    
Severity: Normal CC: annevk, kkinnunen, webkit-bug-importer
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   
See Also: https://bugs.webkit.org/show_bug.cgi?id=247690
Bug Depends on:    
Bug Blocks: 203215    

Description Chris Dumez 2023-01-24 10:14:04 PST
The Clear-Site-Data HTTP header should obey origin partition. If shouldn't be possible for an iframe of origin A under top origin B to be able to clear site data from top origin A (and vice-versa).
Our storages are partitioned and the request to clear site data should respect that.
Comment 1 Chris Dumez 2023-01-24 10:18:13 PST
Pull request: https://github.com/WebKit/WebKit/pull/9053
Comment 2 EWS 2023-01-26 20:49:44 PST
Committed 259466@main (472954140c35): <https://commits.webkit.org/259466@main>

Reviewed commits have been landed. Closing PR #9053 and removing active labels.
Comment 3 Radar WebKit Bug Importer 2023-01-26 20:50:19 PST
<rdar://problem/104727671>