A client of ours wants us to host a blob of Javascript for their custom-branded version of our website. It is hosted on a subdomain of our site (customer.example.com
), but uses the same cookie domain as our primary site (example.com
).
What are the security implications of doing this, should we agree?