Issue metadata
Sign in to add a comment
|
SameSite cookies are not used in a new browser tab on the first request
Reported by
kyle.zee...@gmail.com,
Jun 15 2016
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.84 Safari/537.36 Steps to reproduce the problem: NB This is a security bug only in that it involves cookies. The browser behaviour is to fail closed so I don't see this as being a security vulnerability. Steps: 1. In "tab1" load a URL for a page (e.g., foo.com/) where the HTTP response sets two cookies: -"with_same_site=cats; path=/app; HttpOnly; SameSite=Strict" -"without_same_site=dogs; path=/app; HttpOnly" 2. IN A NEW TAB ("tab2"), load foo.com/app/bar and inspect the cookies that were added to the HTTP request sent to foo.com/app/bar. 3. In "tab2" the Hit refresh and inspect the cookies that were added to the HTTP request sent to foo.com/app/bar. NB I dont think the path=/app is relevant but thats how I reproduced it. What is the expected behavior? For both requests to foo.com/app/bar I should see both the with_same_site and the without_same_site cookies. What went wrong? In the first request to foo.com/app/bar I do not see the "with_same_site" cookie. In the second request I do see the "with_same_site" cookie. In both requests I do see the "without_same_site" cookie. Did this work before? No Chrome version: 51.0.2704.84 Channel: stable OS Version: OS X 10.11.4 Flash Version: Shockwave Flash 21.0 r0 The last samesite bug I filed was handled by rsleevi@chromium.org and was filed under Component : Blink>SecurityFeatureInternals>Network>Cookies
,
Jun 16 2016
Actually, just realized that this is a duplicate. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by est...@chromium.org
, Jun 15 2016Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Owner: mkwst@chromium.org