Globally Scoped Http Authentication Cache
Configures a single global per profile cache with HTTP server authentication credentials.
- (Default) HTTP authentication credentials are scoped to top-level sites—For version 80 and later, Chromium scopes HTTP server authentication credentials by top-level site. If two sites use resources from the same authenticating domain, credentials need to be provided independently in the context of both sites and cached proxy credentials are reused across sites.
- HTTP authentication credentials entered in the context of one site will automatically be used in the context of another—This can leave sites open to some types of cross-site attacks. It also allows users to be tracked across sites, even without cookies, by adding entries to the HTTP authentication cache using credentials embedded in URLs.
This policy is intended to give organizations depending on the legacy behavior a chance to update their sign-in procedures, and will be removed in the future.