| Summary: | Service Worker breaks sameSite=lax cookies | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | erik.witt |
| Component: | Service Workers | Assignee: | Nobody <webkit-unassigned> |
| Status: | RESOLVED DUPLICATE | ||
| Severity: | Blocker | CC: | achristensen, webkit-bug-importer, wilander, youennf |
| Priority: | P2 | Keywords: | InRadar |
| Version: | Safari 15 | ||
| Hardware: | All | ||
| OS: | All | ||
| See Also: | https://bugs.webkit.org/show_bug.cgi?id=233128 | ||
|
Description
erik.witt
2021-10-28 10:18:25 PDT
Hi folks, can we add any more information on the issue? This is a big blocker for us on Safari at the moment and we are happy to assist Any updates on this? Has been two weeks, still happy to help if there are open questions Hey again, don't you consider this issue important or why the lack of any response? Thanks for the repro steps, Erik, I can confirm the behavior you described locally. It seems I can reproduce when using page cache (using back) but not if I am loading the page, then loading google.com manually, then reloading the page by manually entering the URL in the address bar. Hey, yes, I see the same thing. Using the address bar at all seems to set the context to same site. In that case even the sameSite=strict cookies send, I think. However using the back button (and afterwards reloading via ctrl+r) results in the issue but also when you follow a link e.g. from Google. We actually would this issue on production pages when navigating from an external payment provider (PayPal) back to the page. In that case the session was cleared and the order process aborted because of it. Hi all! Any news on this issue? Hey, do you have any update on this? Thanks Erik for the repro steps, I think this is a dupe of bug 226386 and this can be fixed there. *** This bug has been marked as a duplicate of bug 226386 *** |