Hacker News new | past | comments | ask | show | jobs | submit login

It's actually because Youtube is integrated properly into their auth flow. It's so when you login to one of google's websites and visit another, you are already logged on and don't have to go through the auth-flow.

i.e. Without this trick, if you logged into gmail and then went to YouTube you would have to sign in again. This is because the YouTube.com domain can't access the mail.google.com cookie because of the same-origin policy.

(Note: Even if you use cross-origin resource sharing headers, cookies will still not work across domains for all users as several browsers such as Safari have third-party cookies disabled by default which stops the ability of sharing cookies over CORS).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: