Based on the assumption that two web origins being affiliated (in terms of AffiliationService) is the same level of trust between them as having the same registerable domain, we should allow to fill credentials from one affiliated website on another in the same way we do for PSL matched credentials.
This bug tracks obtaining a security confirmation that the assumption is correct, and implementing the change in behaviour.
Comment 1 by jww@chromium.org
, Jul 22 2016