logoalt Hacker News

louiskottmanntoday at 5:50 AM1 replyview on HN

I appreciate that, but in the case of TLS or CSRF tokens the server is not blindly trusting the browser in the way Sec-Fetch-Site makes it.


Replies

tptacektoday at 5:55 AM

Sure it is. The same-origin rule that holds the whole web security model together is entirely a property of browser behavior.

show 1 reply