Go to www.google.com, you will see a Local Files entry on the Cookies list of the Web Inspector that has all the same Cookies as Google.
Google creates an about:blank in generating their page, and that is being added to the Cookies domain list, when we should only be adding resources that were loaded from HTTP protocols.
Created attachment 41261 [details]
I am not sure if file URLs can create cookies/should show up in the Cookies list, if they should, then the if statement should be changed to:
if (protocolInHTTPFamily() || protocolIs("file")), but I'm not sure which of these is correct, this patch works, but will not show cookies from a file URL, I'm not sure if that is correct behavior or not.
Dan Bernstein sent me a test case that shows that cookies are allowed on file URLs, so it seems that this bug was mistitled, and the code check is doing the wrong thing, we should also support file:// loads to show the cookies from.
Created attachment 41295 [details]
Fix for HTTP + File URLs
Landed in http://trac.webkit.org/changeset/49883.