<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>246477</bug_id>
          
          <creation_ts>2022-10-13 15:22:05 -0700</creation_ts>
          <short_desc>Cap cookie lifetimes to 7 days for responses from third party IP addresses</short_desc>
          <delta_ts>2023-04-06 10:39:16 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Platform</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Wenson Hsieh">wenson_hsieh</reporter>
          <assigned_to name="Wenson Hsieh">wenson_hsieh</assigned_to>
          <cc>blare-seabeds-0x</cc>
    
    <cc>dmdabbs</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1905445</commentid>
    <comment_count>0</comment_count>
    <who name="Wenson Hsieh">wenson_hsieh</who>
    <bug_when>2022-10-13 15:22:05 -0700</bug_when>
    <thetext>rdar://100831206</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1905448</commentid>
    <comment_count>1</comment_count>
    <who name="Wenson Hsieh">wenson_hsieh</who>
    <bug_when>2022-10-13 15:49:38 -0700</bug_when>
    <thetext>Pull request: https://github.com/WebKit/WebKit/pull/5347</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1907427</commentid>
    <comment_count>2</comment_count>
    <who name="EWS">ews-feeder</who>
    <bug_when>2022-10-21 14:37:31 -0700</bug_when>
    <thetext>Committed 255849@main (b0305b173106): &lt;https://commits.webkit.org/255849@main&gt;

Reviewed commits have been landed. Closing PR #5347 and removing active labels.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1911740</commentid>
    <comment_count>3</comment_count>
    <who name="">blare-seabeds-0x</who>
    <bug_when>2022-11-10 21:48:44 -0800</bug_when>
    <thetext>Hi Wenson Hsieh,

I am trying to understand more about this fix. I tried this on preview and it looks quite a huge change with a lot of side effects for valid use cases.

If I am not mistaken this use cases will be now broken:

1) I have services that are running in multiple infrastructures. Like site is cached on some CDN, where my auth server is running on Heroku, where processing is done on AWS (one main domain and two subdomains with different IP&apos;s). Because of that my own services are limited now. Using multiple infrastructures in completely first party mode (I own everything) is legit use case.

2) I have headless shop on Shopify. This means that my html/css/js is hosted on some CDN let&apos;s say Vercel, but I am using Shopify API&apos;s to run the store. This now means that user will be limited to 7 days for everything related to Shopify.

Would love to hear more about this change. 


Thank you</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>