From Chrome 80, as part of a staged rollout, the default behavior of cookies will be changing. Cookies without a SameSite attribute will be treated as if they had SameSite=Lax set, which will restrict them to first-party only. Cookies for third-party contexts must be marked with SameSite=None; Secure. Enable this behavior in Chrome now and start testing your sites to make sure you’re ready for the change!
Links:
SameSite Updates →
SameSite cookies explained →
1 view
354
81
9 months ago 00:04:16 2
SameSite Cookies for Everyone - Cross Site Request Forgery Mitigations (follow up)
9 months ago 00:13:56 1
SameSite Cookie Attribute Explained by Example (Strict, Lax, None & No SameSite)
9 months ago 00:11:33 1
SameSite Cookies Explained ~ With Examples
2 years ago 00:54:36 1
Tutorial - Part 6 | Authentication for API Routes using JWT and bcrypt
4 years ago 00:35:33 9
CSRF-уязвимости все еще актуальны / Михаил Егоров (Odin — Ingram Micro)
4 years ago 00:21:27 1
Cookie recipes - SameSite and beyond || Google Chrome Developers