Resource / Blogs /

Understanding the Difference Between SameSite and SameOrigin

By
Vaibhav Rajput
July 17, 2023
6 min
Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

Key Takeaways

  • Same-origin means the scheme, host and port all match exactly.
  • Same-site means the scheme and registrable domain (eTLD+1) match.
  • Subdomains of one registrable domain are same-site but cross-origin.
  • The Public Suffix List stops shared hosts like github.io from being treated as one site.
  • Browsers set the Sec-Fetch-Site header, and scripts can't change it.
  • Cross-site request abuse enables attacks like Cross-Site WebSocket Hijacking.

You might have come across both “same-site” and “same-origin”, and although they look and sound similar, these terms are among the highly cited but often misunderstood terms. Let us get rid of the confusion by understanding what these terms mean.

Same Origin

According to WHATWG spec, Origins are considered the fundamental currency of the web security model. An origin can be either an opaque origin or a tuple origin.

Opaque Origin

Opaque origins can be thought of as origins that appear under unusual circumstances. For example, when you open a file locally, the URL would be something like file:///, in this case, the origin will be an opaque origin, which is null.

Picture explaining what is opaque origin

Tuple Origin

Tuple origin is the origin that we all commonly know, as is what everyone is concerned about. A tuple origin consists of  

  • A scheme (ASCII string)
  • A host
  • A port (null or 16-bit unsigned integer)
  • A domain (null or a domain). Null unless stated otherwise.

The algorithm that decides if two origins (Origin A and Origin B) are of the same origin is:

  1. If A and B are the same opaque origin, then return true.
  1. If A and B are both tuple origin and their scheme, hosts, and port are identical, then return true.
  1. Return false.

This might be a bit confusing as to why we include the domain in the tuple when we already have a host in the tuple. The answer lies in the domain part of the tuple. The domain part of the tuple can be modified using document.domain setter, though the modern browser has disabled this feature. The tuple is then serialized to obtain a string, which is what we get when we use something like window.origin.

Picture explaining what tuple origin is.

In simpler terms, this can be understood as – If a website has the same scheme, hostname, and port, it is considered as same-origin; everything else is considered cross-origin. Now let us understand what it means with the help of an example.

Suggested Read: Web Services and Its Attack Types

Same Site

The site is considered as the combination of TLD, scheme and domain name. So, if we take http://blog.example.com as an example, the site would be http://example.com. Now if it is just this much, it is easier to identify site but for TLDs such as co.in or gov.in there is no way to algorithmically figure out the registrable domain which is also known as “eTLD+1”. A registrable domain is a domain formed by the most specific public suffix, along with the domain label immediately preceding it. Now, why do we need something like this? Let us understand with the help of an example. GitHub page is a service that allows anyone to host a static website with a domain like <username>.github.io. Let us say there are two users called Alice and Bob, who both own alice.github.io and bob.github.io, respectively. Now if there was no concept of a public suffix list, both alice.github.io and bob.github.io would be considered as same-site, but GitHub doesn’t want bob.github.io to interfere with alice.github.io, hence they added an entry for github.io in public suffix list, what this means is that the registrable domain of alice.github.io is not github.io but alice.github.io itself and github.io is considered eTLD, which is why both alice.github.io and bob.github.io are not considered a part of the site. Site, in simpler terms, is equivalent to the registrable domain.

Picture explaining what is eTLD in same site.

“Same site” and “Cross-site” requests

Websites that share the same scheme and the same registrable domain are considered “same-site”, Websites with a different scheme or different registrable domain are considered “cross-site”. Let us understand this with an example.

  1. A request from http://blog.example.com to http://dev.example.com is considered the same site because they share the same scheme and registrable domain.
  1. A request from https://blog.example.com to http://dev.example.com is considered cross-site because they share different schemes.
  1. A request from http://blog.example.com to http://dev.example.org is considered cross-site because they have a different registrable domain.

It is worth noting that the WHATWG spec was updated to include the scheme as well. Previously, the same site only checked for eTLD+1, which was then updated to introduce a new term in WHATWG spec called schemelessly same-site. Abusing cross-site requests is one of the common web vulnerabilities that can lead to attacks like Cross-Site Web Socket Hijacking (CSWSH).  

How to check if a request is “same-origin”, “same-site”, or “cross-site”?

All modern browsers send requests along with the Sec-Fetch-Site HTTP header. The header can only have one of the following values.

  • cross-site
  • same origin
  • same site
  • none

You can trust the value of these headers since they are added by browsers and is a forbidden header name, meaning the value of these headers cannot be modified programmatically.

Summary

Let us briefly review what we learned.

References

‍

Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.
Author
Vaibhav Rajput
Ex-Bandit
Red arrow pointing diagonally upward to the right.Red arrow pointing diagonally upward to the right.

Keep Reading

For Security Leaders
Agentic AI Security: The Hidden Attack Surface Beyond Prompt Injection
August 25, 2026
10 min
For Security Leaders
Research & disclosures
Binwalk Path Traversal Vulnerability: Turning Firmware Analysis into Code Execution
August 26, 2026
8 min
Guides & tutorials
For Security Leaders
An Introduction to Smali
August 26, 2026
8 min
Dark scene with vertical thin orange lines resembling distant illuminated bars or streaks against a black background and a faint horizontal red glow near the bottom.