samedi 31 juillet 2021

Browser rejects cookie if it is in a cross-site context and has strict same-site attribute

My server set same-site cookie on my client. every thing works fine if both server and client are on the same domain but when they are not on the same domain the browser rejects the cookie and i get the console warning shown in the attached image. i'm confused with the term "same-site" does it mean server and client should be hosted on the same domain or the browser sends the cookie only for same-site requests (that is, requests originating from the same site that set the cookie). If the request originated from a different URL than the current one, no cookies with the SameSite=Strict attribute are sent. browser console




Aucun commentaire:

Enregistrer un commentaire