DS-ProdFlow — Notion Embed Probe
Answers OQ-1 (iframe sandbox / popup) and OQ-2 (partitioned cookies).
Embed this page in a Notion page, then click both buttons.
Verdict
OQ-1 — Can the auth popup open?not tested
OQ-1b — Does the popup escape the sandbox?not tested
OQ-2 — Do partitioned cookies work?not tested
OQ-2b — Is Storage Access available?not tested
Overall — popup auth design viable?run the tests
Frame context
Storage & cookies
A JS-set cookie is a proxy for a server
Set-Cookie, not identical to it.
HttpOnly cannot be tested from script. Confirm against a real server response
before treating the session design as proven.Popup result
| Not tested yet. |