Covers cross-origin reuse of session-like material through headers, beacons, WebSocket/WebRTC, and postMessage.
No source primed yet.