| Summary: | SameSite Strict cookies are not sent via WebSocket on any restored/cache-loaded tabs, irreparably breaking applications and services that authenticate over WebSocket | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | Peter Sipos <schipy3> |
| Component: | Page Loading | Assignee: | Nobody <webkit-unassigned> |
| Status: | RESOLVED CONFIGURATION CHANGED | ||
| Severity: | Major | CC: | achristensen, ap, beidson, youennf |
| Priority: | P2 | ||
| Version: | Safari 14 | ||
| Hardware: | Unspecified | ||
| OS: | All | ||
|
Description
Peter Sipos
2021-11-03 07:06:09 PDT
> Experienced on Safari 14, Safari 15 - it seems to be fixed on Safari 15.1 (did not find the relevant fixed webkit report though)
> Even if fixed in 15.1, backport seems to be justified given the scope and implications of the issue.
We cannot go back in time to change what's already on customers' machines. Please upgrade to the latest release.
- I can't confirm 100% that the issue is completely fixed in 15.1 (given the broad number of tab open use-cases, there could be ones that are still not fixed), we could not reproduce the crash-restore and reopen last closed tab cases, but did not test others - also no time machine is needed, you can release patches to still supported major versions of your software like non-arrogant teams do - MacOS Big Sur / Safari 14 is still a supported, is it not? It would be most appreciated if you could file a new bug for the exact case(s) that you can confirm to still be broken in 15.1. This bug report is just saying that something could be broken, and you would like us to test that. One of the folks CC'ed here may or may not be willing to test, but as far as I'm concerned, there is no reason to keep an open bug about something that hasn't been observed with the latest release yet. WebKit Bugzilla is for tracking issues that occur with latest WebKit code. We are not tracking or discussing when vendors release the fixes. |