Skip to content

Which cookies are sent with FedCM requests? #824

@ThisIsMissEm

Description

@ThisIsMissEm

I have a bit of a weird use-case in mind for FedCM where I have a single page application which has previously performed authentication using something like the OAuth Password Grant Flow — essentially username + password typed into the SPA, even though it is not actually the identity provider. That's the context for this question.

When reading the FedCM spec, it just says we include cookies following credentials: include from fetch, but there isn't anything that explicitly says if client-side set cookies would or would not be included. It seems likely that they are included, but I'm just trying to gain some certainty around this.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions