New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 600983 link

Starred by 3 users

Issue metadata

Status: Fixed
Owner:
Buried. Ping if important.
Closed: Apr 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug

Blocking:
issue 459154



Sign in to add a comment

A "SameSite" attribute which has no value or has an invalid value should have the same effect as SameSite=Strict

Reported by l446240525@gmail.com, Apr 6 2016

Issue description

spec: https://tools.ietf.org/html/draft-west-first-party-cookies-06#section-3.2

This is a cookie parser (cookies/parsed_cookie.cc) bug.
 

Comment 1 by mkwst@chromium.org, Apr 6 2016

Blocking: 459154
Components: Internals>Network>Cookies Blink>SecurityFeature
Labels: -Pri-3 M-51 Pri-2
Owner: mkwst@chromium.org
Status: Assigned (was: Unconfirmed)

Comment 2 by mkwst@chromium.org, Apr 6 2016

I think this is probably actually both a spec and implementation bug. We should ignore cookies with an invalid 'SameSite' attribute.

Comment 3 by mkwst@chromium.org, Apr 6 2016

https://codereview.chromium.org/1868493002 out for review.

Comment 5 by mkwst@chromium.org, Apr 7 2016

Status: Fixed (was: Assigned)
 Issue 617569  has been merged into this issue.
The spec changed in 2018 and the behavior here was changed in  Issue 635882 . Now, a cookie with an empty or invalid SameSite attribute value ignores the SameSite attribute, treating the cookie as a plain cookie with no restrictions.

Sign in to add a comment