On 03/10/2015 03:35 AM, Antonio Manuel Amaya Calvo wrote:

> From a security point of view, I think the cookie jar model is much
> better than having everything on the same pile. Maybe rather than
> getting rid of that, or even making it an opt-in feature we could try
> and hide the implementation details from the content. So we keep a
> cookie jar per origin (instead of per-app as we do know, which is really
> the same since we can only have one app per origin) and every time that

Nit: we currently support multiple apps per origin - the app identifier
is the manifest url.

Fabrice Desré
b2g team
Mozilla Corporation
dev-b2g mailing list

Reply via email to