Files
sousa-gecko/testing/web-platform/tests/fledge/tentative/cross-origin-embedder-policy.https.window.js.headers
T
Matt Menke 076e3cbaae Bug 1958543 [wpt PR 51862] - [Protected Audience] Clear most of ClientSecurityState for PA fetches., a=testonly
Automatic update from web-platform-tests
[Protected Audience] Clear most of ClientSecurityState for PA fetches.

Make the ClientSecurityState used by Protected Audience fetches only
have populated `ip_address_space`, `is_web_secure_context`, and
`private_network_request_policy` fields. This both matches the spec,
and avoids leaking data through reports from requests that should be
isolated from the page running the auction.

Bug: 385152122
Change-Id: If5ffcbd5fcd489da92157a633eb384f38fa2b1ef
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6426692
Commit-Queue: mmenke <mmenke@chromium.org>
Reviewed-by: Maks Orlovich <morlovich@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1442908}

--

wpt-commits: 18c417a8d3cd595c15502ba4b90d8786caa20188
wpt-pr: 51862
2025-04-09 11:12:46 +00:00

1 line
42 B
Plaintext

Cross-Origin-Embedder-Policy: require-corp