@techreport{west-cookie-samesite-firstparty-01, number = {draft-west-cookie-samesite-firstparty-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-west-cookie-samesite-firstparty/01/}, author = {Mike West}, title = {{First-Party Sets and SameSite Cookies}}, pagetotal = 9, year = 2019, month = may, day = 10, abstract = {This document proposes the addition of two new values to the "SameSite" cookie attribute defined in RFC6265bis {[}I-D.ietf-httpbis-rfc6265bis{]}: "FirstPartyLax" and "FirstPartyStrict". These values are conceptually similar to the existing "Lax" and "Strict" values, but base the delivery checks on the First-Party Sets {[}first-party-set{]} of a request's initiator and target, rather than on their respective registrable domains. This widens the scope of a given cookie's applicability, enabling entities that have sharded themselves across multiple registrable domains to maintain HTTP state without exposing themselves to the risks of "SameSite=None".}, }