same-site-cookie-attribute.json 7.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384
  1. {
  2. "title":"'SameSite' cookie attribute",
  3. "description":"Same-site cookies (\"First-Party-Only\" or \"First-Party\") allow servers to mitigate the risk of CSRF and information leakage attacks by asserting that a particular cookie should only be sent with requests initiated from the same registrable domain.",
  4. "spec":"https://tools.ietf.org/html/draft-west-first-party-cookies-06",
  5. "status":"other",
  6. "links":[
  7. {
  8. "url":"http://www.sjoerdlangkemper.nl/2016/04/14/preventing-csrf-with-samesite-cookie-attribute/",
  9. "title":"Preventing CSRF with the same-site cookie attribute"
  10. },
  11. {
  12. "url":"https://bugzilla.mozilla.org/show_bug.cgi?id=795346",
  13. "title":"Mozilla Bug #795346: Add SameSite support for cookies"
  14. },
  15. {
  16. "url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1286861",
  17. "title":"Mozilla Bug #1286861, includes the patches that landed SameSite support in Firefox"
  18. },
  19. {
  20. "url":"https://wpdev.uservoice.com/forums/257854-microsoft-edge-developer/suggestions/17140412-support-samesite-cookie-option",
  21. "title":"Microsoft Edge feature request on UserVoice"
  22. },
  23. {
  24. "url":"https://developer.microsoft.com/en-us/microsoft-edge/platform/status/samesitecookies/",
  25. "title":"Microsoft Edge Browser Status"
  26. },
  27. {
  28. "url":"https://blogs.windows.com/msedgedev/2018/05/17/samesite-cookies-microsoft-edge-internet-explorer/",
  29. "title":"MS Edge dev blog: \"Previewing support for same-site cookies in Microsoft Edge\""
  30. }
  31. ],
  32. "bugs":[
  33. ],
  34. "categories":[
  35. "Security"
  36. ],
  37. "stats":{
  38. "ie":{
  39. "5.5":"n",
  40. "6":"n",
  41. "7":"n",
  42. "8":"n",
  43. "9":"n",
  44. "10":"n",
  45. "11":"a #1 #2"
  46. },
  47. "edge":{
  48. "12":"n",
  49. "13":"n",
  50. "14":"n",
  51. "15":"n",
  52. "16":"y #1",
  53. "17":"y #1",
  54. "18":"y",
  55. "76":"y"
  56. },
  57. "firefox":{
  58. "2":"n",
  59. "3":"n",
  60. "3.5":"n",
  61. "3.6":"n",
  62. "4":"n",
  63. "5":"n",
  64. "6":"n",
  65. "7":"n",
  66. "8":"n",
  67. "9":"n",
  68. "10":"n",
  69. "11":"n",
  70. "12":"n",
  71. "13":"n",
  72. "14":"n",
  73. "15":"n",
  74. "16":"n",
  75. "17":"n",
  76. "18":"n",
  77. "19":"n",
  78. "20":"n",
  79. "21":"n",
  80. "22":"n",
  81. "23":"n",
  82. "24":"n",
  83. "25":"n",
  84. "26":"n",
  85. "27":"n",
  86. "28":"n",
  87. "29":"n",
  88. "30":"n",
  89. "31":"n",
  90. "32":"n",
  91. "33":"n",
  92. "34":"n",
  93. "35":"n",
  94. "36":"n",
  95. "37":"n",
  96. "38":"n",
  97. "39":"n",
  98. "40":"n",
  99. "41":"n",
  100. "42":"n",
  101. "43":"n",
  102. "44":"n",
  103. "45":"n",
  104. "46":"n",
  105. "47":"n",
  106. "48":"n",
  107. "49":"n",
  108. "50":"n",
  109. "51":"n",
  110. "52":"n",
  111. "53":"n",
  112. "54":"n",
  113. "55":"n",
  114. "56":"n",
  115. "57":"n",
  116. "58":"n",
  117. "59":"n",
  118. "60":"y",
  119. "61":"y",
  120. "62":"y",
  121. "63":"y",
  122. "64":"y",
  123. "65":"y",
  124. "66":"y",
  125. "67":"y",
  126. "68":"y",
  127. "69":"y",
  128. "70":"y",
  129. "71":"y"
  130. },
  131. "chrome":{
  132. "4":"n",
  133. "5":"n",
  134. "6":"n",
  135. "7":"n",
  136. "8":"n",
  137. "9":"n",
  138. "10":"n",
  139. "11":"n",
  140. "12":"n",
  141. "13":"n",
  142. "14":"n",
  143. "15":"n",
  144. "16":"n",
  145. "17":"n",
  146. "18":"n",
  147. "19":"n",
  148. "20":"n",
  149. "21":"n",
  150. "22":"n",
  151. "23":"n",
  152. "24":"n",
  153. "25":"n",
  154. "26":"n",
  155. "27":"n",
  156. "28":"n",
  157. "29":"n",
  158. "30":"n",
  159. "31":"n",
  160. "32":"n",
  161. "33":"n",
  162. "34":"n",
  163. "35":"n",
  164. "36":"n",
  165. "37":"n",
  166. "38":"n",
  167. "39":"n",
  168. "40":"n",
  169. "41":"n",
  170. "42":"n",
  171. "43":"n",
  172. "44":"n",
  173. "45":"n",
  174. "46":"n",
  175. "47":"n",
  176. "48":"n",
  177. "49":"n",
  178. "50":"n",
  179. "51":"y",
  180. "52":"y",
  181. "53":"y",
  182. "54":"y",
  183. "55":"y",
  184. "56":"y",
  185. "57":"y",
  186. "58":"y",
  187. "59":"y",
  188. "60":"y",
  189. "61":"y",
  190. "62":"y",
  191. "63":"y",
  192. "64":"y",
  193. "65":"y",
  194. "66":"y",
  195. "67":"y",
  196. "68":"y",
  197. "69":"y",
  198. "70":"y",
  199. "71":"y",
  200. "72":"y",
  201. "73":"y",
  202. "74":"y",
  203. "75":"y",
  204. "76":"y",
  205. "77":"y",
  206. "78":"y",
  207. "79":"y"
  208. },
  209. "safari":{
  210. "3.1":"n",
  211. "3.2":"n",
  212. "4":"n",
  213. "5":"n",
  214. "5.1":"n",
  215. "6":"n",
  216. "6.1":"n",
  217. "7":"n",
  218. "7.1":"n",
  219. "8":"n",
  220. "9":"n",
  221. "9.1":"n",
  222. "10":"n",
  223. "10.1":"n",
  224. "11":"n",
  225. "11.1":"n",
  226. "12":"y",
  227. "12.1":"y",
  228. "13":"y",
  229. "TP":"y"
  230. },
  231. "opera":{
  232. "9":"n",
  233. "9.5-9.6":"n",
  234. "10.0-10.1":"n",
  235. "10.5":"n",
  236. "10.6":"n",
  237. "11":"n",
  238. "11.1":"n",
  239. "11.5":"n",
  240. "11.6":"n",
  241. "12":"n",
  242. "12.1":"n",
  243. "15":"n",
  244. "16":"n",
  245. "17":"n",
  246. "18":"n",
  247. "19":"n",
  248. "20":"n",
  249. "21":"n",
  250. "22":"n",
  251. "23":"n",
  252. "24":"n",
  253. "25":"n",
  254. "26":"n",
  255. "27":"n",
  256. "28":"n",
  257. "29":"n",
  258. "30":"n",
  259. "31":"n",
  260. "32":"n",
  261. "33":"n",
  262. "34":"n",
  263. "35":"n",
  264. "36":"n",
  265. "37":"n",
  266. "38":"n",
  267. "39":"y",
  268. "40":"y",
  269. "41":"y",
  270. "42":"y",
  271. "43":"y",
  272. "44":"y",
  273. "45":"y",
  274. "46":"y",
  275. "47":"y",
  276. "48":"y",
  277. "49":"y",
  278. "50":"y",
  279. "51":"y",
  280. "52":"y",
  281. "53":"y",
  282. "54":"y",
  283. "55":"y",
  284. "56":"y",
  285. "57":"y",
  286. "58":"y",
  287. "60":"y",
  288. "62":"y"
  289. },
  290. "ios_saf":{
  291. "3.2":"n",
  292. "4.0-4.1":"n",
  293. "4.2-4.3":"n",
  294. "5.0-5.1":"n",
  295. "6.0-6.1":"n",
  296. "7.0-7.1":"n",
  297. "8":"n",
  298. "8.1-8.4":"n",
  299. "9.0-9.2":"n",
  300. "9.3":"n",
  301. "10.0-10.2":"n",
  302. "10.3":"n",
  303. "11.0-11.2":"n",
  304. "11.3-11.4":"n",
  305. "12.0-12.1":"y",
  306. "12.2-12.3":"y",
  307. "13":"y"
  308. },
  309. "op_mini":{
  310. "all":"n"
  311. },
  312. "android":{
  313. "2.1":"n",
  314. "2.2":"n",
  315. "2.3":"n",
  316. "3":"n",
  317. "4":"n",
  318. "4.1":"n",
  319. "4.2-4.3":"n",
  320. "4.4":"n",
  321. "4.4.3-4.4.4":"n",
  322. "67":"y"
  323. },
  324. "bb":{
  325. "7":"n",
  326. "10":"n"
  327. },
  328. "op_mob":{
  329. "10":"n",
  330. "11":"n",
  331. "11.1":"n",
  332. "11.5":"n",
  333. "12":"n",
  334. "12.1":"n",
  335. "46":"y"
  336. },
  337. "and_chr":{
  338. "75":"y"
  339. },
  340. "and_ff":{
  341. "67":"y"
  342. },
  343. "ie_mob":{
  344. "10":"n",
  345. "11":"n"
  346. },
  347. "and_uc":{
  348. "12.12":"n"
  349. },
  350. "samsung":{
  351. "4":"n",
  352. "5.0-5.4":"y",
  353. "6.2-6.4":"y",
  354. "7.2-7.4":"y",
  355. "8.2":"y",
  356. "9.2":"y"
  357. },
  358. "and_qq":{
  359. "1.2":"n"
  360. },
  361. "baidu":{
  362. "7.12":"y"
  363. },
  364. "kaios":{
  365. "2.5":"n"
  366. }
  367. },
  368. "notes":"This feature is backwards compatible. Browsers not supporting this feature will simply use the cookie as a regular cookie. There is no need to deliver different cookies to clients.",
  369. "notes_by_num":{
  370. "1":"Not shipped with the inital release but later with the 2018 June security update (Patch Tuesday) to Windows 10 RS3 (2017 Fall Creators Update) and newer. [More info](https://github.com/MicrosoftEdge/Status/issues/616).",
  371. "2":"Partial support because only supported in IE 11 on Windows 10 RS3 (2017 Fall Creators Update) and newer, but not in IE 11 on other Windows versions (Windows 7, ...)"
  372. },
  373. "usage_perc_y":86.58,
  374. "usage_perc_a":1.74,
  375. "ucprefix":false,
  376. "parent":"",
  377. "keywords":"security,cookies,cookie,csrf",
  378. "ie_id":"",
  379. "chrome_id":"4672634709082112",
  380. "firefox_id":"",
  381. "webkit_id":"",
  382. "shown":true
  383. }