same-site-cookie-attribute.json 5.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282
  1. {
  2. "title":"'SameSite' cookie attribute",
  3. "description":"Same-site cookies (n\u00e9e \"First-Party-Only\" (n\u00e9e \"First-Party\")) allow servers to mitigate the risk of CSRF and information leakage attacks by asserting that a particular cookie should only be sent with requests initiated from the same registrable domain.",
  4. "spec":"https://tools.ietf.org/html/draft-west-first-party-cookies-06",
  5. "status":"other",
  6. "links":[
  7. {
  8. "url":"http://www.sjoerdlangkemper.nl/2016/04/14/preventing-csrf-with-samesite-cookie-attribute/",
  9. "title":"Preventing CSRF with the same-site cookie attribute"
  10. },
  11. {
  12. "url":"https://bugzilla.mozilla.org/show_bug.cgi?id=795346",
  13. "title":"Mozilla Bug #795346: Add SameSite support for cookies"
  14. }
  15. ],
  16. "bugs":[
  17. ],
  18. "categories":[
  19. "Other"
  20. ],
  21. "stats":{
  22. "ie":{
  23. "5.5":"n",
  24. "6":"n",
  25. "7":"n",
  26. "8":"n",
  27. "9":"n",
  28. "10":"n",
  29. "11":"n"
  30. },
  31. "edge":{
  32. "12":"n",
  33. "13":"n",
  34. "14":"n",
  35. "15":"n"
  36. },
  37. "firefox":{
  38. "2":"n",
  39. "3":"n",
  40. "3.5":"n",
  41. "3.6":"n",
  42. "4":"n",
  43. "5":"n",
  44. "6":"n",
  45. "7":"n",
  46. "8":"n",
  47. "9":"n",
  48. "10":"n",
  49. "11":"n",
  50. "12":"n",
  51. "13":"n",
  52. "14":"n",
  53. "15":"n",
  54. "16":"n",
  55. "17":"n",
  56. "18":"n",
  57. "19":"n",
  58. "20":"n",
  59. "21":"n",
  60. "22":"n",
  61. "23":"n",
  62. "24":"n",
  63. "25":"n",
  64. "26":"n",
  65. "27":"n",
  66. "28":"n",
  67. "29":"n",
  68. "30":"n",
  69. "31":"n",
  70. "32":"n",
  71. "33":"n",
  72. "34":"n",
  73. "35":"n",
  74. "36":"n",
  75. "37":"n",
  76. "38":"n",
  77. "39":"n",
  78. "40":"n",
  79. "41":"n",
  80. "42":"n",
  81. "43":"n",
  82. "44":"n",
  83. "45":"n",
  84. "46":"n",
  85. "47":"n",
  86. "48":"n",
  87. "49":"n",
  88. "50":"n",
  89. "51":"n",
  90. "52":"n",
  91. "53":"n"
  92. },
  93. "chrome":{
  94. "4":"n",
  95. "5":"n",
  96. "6":"n",
  97. "7":"n",
  98. "8":"n",
  99. "9":"n",
  100. "10":"n",
  101. "11":"n",
  102. "12":"n",
  103. "13":"n",
  104. "14":"n",
  105. "15":"n",
  106. "16":"n",
  107. "17":"n",
  108. "18":"n",
  109. "19":"n",
  110. "20":"n",
  111. "21":"n",
  112. "22":"n",
  113. "23":"n",
  114. "24":"n",
  115. "25":"n",
  116. "26":"n",
  117. "27":"n",
  118. "28":"n",
  119. "29":"n",
  120. "30":"n",
  121. "31":"n",
  122. "32":"n",
  123. "33":"n",
  124. "34":"n",
  125. "35":"n",
  126. "36":"n",
  127. "37":"n",
  128. "38":"n",
  129. "39":"n",
  130. "40":"n",
  131. "41":"n",
  132. "42":"n",
  133. "43":"n",
  134. "44":"n",
  135. "45":"n",
  136. "46":"n",
  137. "47":"n",
  138. "48":"n",
  139. "49":"n",
  140. "50":"n",
  141. "51":"y",
  142. "52":"y",
  143. "53":"y",
  144. "54":"y",
  145. "55":"y",
  146. "56":"y",
  147. "57":"y",
  148. "58":"y"
  149. },
  150. "safari":{
  151. "3.1":"n",
  152. "3.2":"n",
  153. "4":"n",
  154. "5":"n",
  155. "5.1":"n",
  156. "6":"n",
  157. "6.1":"n",
  158. "7":"n",
  159. "7.1":"n",
  160. "8":"n",
  161. "9":"n",
  162. "9.1":"n",
  163. "10":"n",
  164. "TP":"n"
  165. },
  166. "opera":{
  167. "9":"n",
  168. "9.5-9.6":"n",
  169. "10.0-10.1":"n",
  170. "10.5":"n",
  171. "10.6":"n",
  172. "11":"n",
  173. "11.1":"n",
  174. "11.5":"n",
  175. "11.6":"n",
  176. "12":"n",
  177. "12.1":"n",
  178. "15":"n",
  179. "16":"n",
  180. "17":"n",
  181. "18":"n",
  182. "19":"n",
  183. "20":"n",
  184. "21":"n",
  185. "22":"n",
  186. "23":"n",
  187. "24":"n",
  188. "25":"n",
  189. "26":"n",
  190. "27":"n",
  191. "28":"n",
  192. "29":"n",
  193. "30":"n",
  194. "31":"n",
  195. "32":"n",
  196. "33":"n",
  197. "34":"n",
  198. "35":"n",
  199. "36":"n",
  200. "37":"n",
  201. "38":"n",
  202. "39":"y",
  203. "40":"y",
  204. "41":"y",
  205. "42":"y",
  206. "43":"y",
  207. "44":"y"
  208. },
  209. "ios_saf":{
  210. "3.2":"n",
  211. "4.0-4.1":"n",
  212. "4.2-4.3":"n",
  213. "5.0-5.1":"n",
  214. "6.0-6.1":"n",
  215. "7.0-7.1":"n",
  216. "8":"n",
  217. "8.1-8.4":"n",
  218. "9.0-9.2":"n",
  219. "9.3":"n",
  220. "10.0-10.2":"n"
  221. },
  222. "op_mini":{
  223. "all":"n"
  224. },
  225. "android":{
  226. "2.1":"n",
  227. "2.2":"n",
  228. "2.3":"n",
  229. "3":"n",
  230. "4":"n",
  231. "4.1":"n",
  232. "4.2-4.3":"n",
  233. "4.4":"n",
  234. "4.4.3-4.4.4":"n",
  235. "53":"y"
  236. },
  237. "bb":{
  238. "7":"n",
  239. "10":"n"
  240. },
  241. "op_mob":{
  242. "10":"n",
  243. "11":"n",
  244. "11.1":"n",
  245. "11.5":"n",
  246. "12":"n",
  247. "12.1":"n",
  248. "37":"n"
  249. },
  250. "and_chr":{
  251. "55":"y"
  252. },
  253. "and_ff":{
  254. "50":"n"
  255. },
  256. "ie_mob":{
  257. "10":"n",
  258. "11":"n"
  259. },
  260. "and_uc":{
  261. "11":"n"
  262. },
  263. "samsung":{
  264. "4":"n"
  265. }
  266. },
  267. "notes":"This feature is backwards compatible. Browsers not supporting this feature will simply use the cookie as a regular cookie. There is no need to deliver different cookies to clients.",
  268. "notes_by_num":{
  269. },
  270. "usage_perc_y":48.92,
  271. "usage_perc_a":0,
  272. "ucprefix":false,
  273. "parent":"",
  274. "keywords":"security,cookies,cookie,csrf",
  275. "ie_id":"",
  276. "chrome_id":"4672634709082112",
  277. "firefox_id":"",
  278. "webkit_id":"",
  279. "shown":true
  280. }