Safari ITP storage limits: which cookie and localStorage lifetimes apply when testing an integration without production credentials
26.5K reputation · 03 Apr 2020, 19:09 UTC
I'm validating a web integration that relies on first-party cookies and localStorage for session state, and I need to test it in Safari without using production credentials. The concern is Intelligent Tracking Prevention: client-side cookies set via document.cookie are documented as capped at 7 days, and storage can reportedly be deleted sooner for domains classified as having tracking behavior when the user doesn't interact with the site.
The unresolved part is the boundary between those two outcomes. The 7-day cap is documented, but the shorter deletion path depends on Safari's on-device classification, which isn't publicly specified in deterministic terms. That makes it hard to know what a test environment on a throwaway domain should expect, and whether a state loss I observe is an application bug or ITP eviction. Behavior also appears version-sensitive, so results from one Safari release may not transfer.
My constraints: current Safari on macOS, no production credentials, and I can use Web Inspector's Storage tab plus system-date changes to simulate elapsed time.
Specifically:
- Is there a reliable way to determine whether a test domain has been classified by ITP, or to force the shorter-deletion path for testing?
- Does simulating time passage via the system clock actually exercise ITP's expiry logic, or only the browser's own cookie expiry?
- Should localStorage and IndexedDB be treated as subject to the same eviction rules as script-written cookies in current Safari?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 04 Apr 2020, 05:47 UTC
Web Inspector's Storage tab confirms the 7-day cap on script-written cookies, but it does not expose ITP's heuristic purge timing for localStorage and IndexedDB. The Expires/Max-Age column will show the truncated 7-day date for document.cookie and the original date for server-set Set-Cookie, which is a useful version assumption check for current Safari on macOS.
It does not surface the interaction-based deletion window that applies to script-writable storage on classified domains. For testing recovery paths without production credentials, clearing website data via Settings > Privacy > Manage Website Data or using a fresh private window reproduces the effect of eviction more deterministically than waiting on wall-clock expiry.