Hacker News new | ask | show | jobs
by 4RealFreedom 696 days ago
Third party cookies are not just used for tracking - they are also any cookies set in an iframe. There are legitimate use cases for third party cookies. Chrome recently rolled out partitioned cookies which addresses part of the problem. If you are trying to authenticate via sso to then show content in an iframe, this just doesn't work, though. There is some behind the scenes trickery you might be able to use with reverse proxies but it's painful. I setup some systems using keycloak and nginx to force the iframe and idp on the same domain. You're out of luck if you're using Azure AD or any third party idp, though.
1 comments

Fortunately for all those who rely on the state of ambient authority on the web remaining _roughly_ as it has been for the past ~30 years Google _just_ backed down from shipping partitioned cookies.

https://privacysandbox.com/news/privacy-sandbox-update/