vulns.co
/
GKData.io MCP

Privacy Community Group · 1 min read

Storage Access API: permission, document activation and cookie eligibility

The API draft distinguishes permission for the top-level and embedded site pair from activated access in a document and cookie eligibility on each request. Secure context, origin, embedding-policy and sandbox conditions still apply. Navigation and redirects constrain continuity; a document's access does not authorize arbitrary cross-origin cookie attachment. The companion Headers draft adds resource-controlled activation of an existing permission, independently of permission to read cross-origin responses.

Open the reference Technical StandardReviewed 2026-10-04

How to use this reference

Editorial guidance: model permission, document access and request eligibility separately. Review denial, revocation and navigation paths, minimize resource opt-in, and retain independent server authorization and CSRF defenses. Cookie availability does not establish authority for a business action.

Before reading

  • Same-site versus same-origin relationships, embedded documents and HTTP cookies

Context and limits

  • Both publications are Draft Community Group Reports. The API draft is outside W3C's standards track and is not a WHATWG Living Standard. The technical-standard taxonomy includes drafts; listed authors are the API's current editors.
  • The companion Headers draft displays 17 December 2025. Its opt-in uses an existing grant; it does not create initial permission. Cookie attachment and CORS response readability remain separate decisions.
  • Document activation here means enabled storage access, distinct from a user gesture. A stored permission alone does not establish current document access; the API considers revocation and masks denied permission-query state.
  • This record focuses on HTTP cookies. Non-cookie extensions, browser parity and deployed conformance are not established by this review.

Sources and provenance

  1. The Storage Access API Privacy Community Group · reviewed 2026-10-04
  2. Storage Access Headers Privacy Community Group · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software