Intelligent Tracking Prevention 2.1
webkit.org
webkit.org
Predictable, but still a bit depressing to read.
My appreciation to the WebKit team for working so diligently on behalf of their users.
https://blog.appfigures.com/shazam-for-ios-sheds-3rd-party-s...
We're currently about to push an update to our system that uses a http only cookie on the shared 'action' domain and writes non-sensitive JWT to client domains for pre-fill and sending action data to CRM/ESP with document.cookie
Now, I am leaning towards rethinking the client side and potentially just move everything to hosted subdomains so we can set http only JWT on client domains - would echo out a JS var with the user so JS can still access instead of document.cookie. Critically this JWT contains not login / donation / sensitive info I assume it's publicly accessible even though we dont have 3rd party JS outside of GA on these domains.
I guess could just keep current setup with identity http only cookie on separate domain and just return JWT in a JSONP/cors request only send it back for 'verified' domains. But that seems hacky and adds http trips (and critically for pre-fill etc want it to be instant not flickered), though would be a lot easier than managing a bunch of subdomain cname stuff.
1. https://groups.google.com/d/msgid/django-developers/20d7a1d1...