Skip to content

DBSC: support site scope registration from subdomains #67827

Description

@rokonec

Is there an existing issue for this?

  • I have searched the existing issues

Is your feature request related to a problem? Please describe the problem.

The experimental DBSC support can emit a valid site-scoped session when registration is served from the registrable-domain root, such as https://example.com. It cannot support registration served from a subdomain, such as https://api.example.com, requesting root site scope at https://example.com.

The current scope origin is derived from the registration request origin. With include_site: true, Chromium requires the scope origin host to be the registrable-domain root, so the subdomain topology needs additional server configuration and root-host authorization.

Describe the solution you'd like

Design support for subdomain registration requesting root site scope, including:

  • Explicit configuration for the DBSC scope origin, separate from the registration request origin.
  • Public Suffix List/registrable-domain validation so configured origins cannot widen scope beyond the registration site.
  • An ownership and composition model for the root /.well-known/device-bound-sessions resource.
  • Configuration of the well-known response's registering_origins entries for authorized registration subdomains.
  • Multi-host Chromium integration tests covering registration on a subdomain, root site scope, sibling destinations, refresh initiators, and cookie-domain variants.

Cookie Domain should remain independently configured; enabling site scope must not automatically widen cookie applicability.

Additional context

This is a follow-up to #66478 and #67388. Root-host registration with site scope remains valid and does not require the registering_origins well-known check. This issue covers only the deferred subdomain-to-root topology.

Activity

  1. rokonec commented on Jul 16, 2026

    @rokonec
    MemberAuthor

    Related design track: #67850 covers separating browser-advertised registration/refresh endpoint URLs from the local handler paths. That determines where DBSC protocol requests are sent; this issue separately covers a subdomain registration requesting registrable-domain-root site scope and its well-known authorization. The designs should be coordinated, but neither implies the other.

  2. added
    area-authIncludes: authentication, authorization, OAuth, OIDC, and access token validation
    on Sep 2, 2026
  3. added this to the .NET 12 Planning milestone on Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-authIncludes: authentication, authorization, OAuth, OIDC, and access token validation

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions