And then these days I have no idea if I can just accept a website's advertising cookies and expect Firefox to block them anyways, or if clicking on such a button would disable the browser's tracking protection.
And then these days I have no idea if I can just accept a website's advertising cookies and expect Firefox to block them anyways, or if clicking on such a button would disable the browser's tracking protection.
So if you visit games.example which loads tracker.example it can set cookies. However these cookies are only used while you are on games.example. If you start browsing comics.example which also loads tracker.example it will start with no cookies, but can set cookies that only affect comics.example.
This way cross-site cookies can still be used for auth, experiments, spam protection or whatever else. But you can't do cross-site tracking as each top-level site had a separate cookie jar.
You could dodge around that with 'open in new window' but it was a pain in the ass. I think they've fixed it recently.
I had my clients just enable it on the browser.
I've only ever seen it for explicitly supported authentication flows by the first-party site.
I think the previous poster was responding to this:
“I'm not sure what people are doing now, because you can't retain state.”
They do OAuth.
There is no replacement. It's just not possible anymore. OAuth doesn't address this.
You can’t do an iframe, but you can still get the data if it’s supported by their api and yours.
Which is the way it should be, imo.