New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 620204 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 619603
Owner:
Buried. Ping if important.
Closed: Jun 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

SameSite cookies are not used in a new browser tab on the first request

Reported by kyle.zee...@gmail.com, Jun 15 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.84 Safari/537.36

Steps to reproduce the problem:
NB This is a security bug only in that it involves cookies. The browser behaviour is to fail closed so I don't see this as being a security vulnerability.

Steps:
1. In "tab1" load a URL for a page (e.g., foo.com/) where the HTTP response sets two cookies:
  -"with_same_site=cats; path=/app; HttpOnly; SameSite=Strict"
  -"without_same_site=dogs; path=/app; HttpOnly"

2. IN A NEW TAB ("tab2"), load foo.com/app/bar and inspect the cookies that were added to the HTTP request sent to foo.com/app/bar.

3. In "tab2" the Hit refresh and inspect the cookies that were added to the HTTP request sent to foo.com/app/bar.

NB I dont think the path=/app is relevant but thats how I reproduced it.

What is the expected behavior?
For both requests to foo.com/app/bar I should see both the with_same_site and the without_same_site cookies.

What went wrong?
In the first request to foo.com/app/bar I do not see the "with_same_site" cookie. 

In the second request I do see the "with_same_site" cookie. 

In both requests I do see the "without_same_site" cookie.

Did this work before? No 

Chrome version: 51.0.2704.84  Channel: stable
OS Version: OS X 10.11.4
Flash Version: Shockwave Flash 21.0 r0

The last samesite bug I filed was handled by rsleevi@chromium.org and was filed under Component : Blink>SecurityFeatureInternals>Network>Cookies
 

Comment 1 by est...@chromium.org, Jun 15 2016

Components: Internals>Network>Cookies Blink>SecurityFeature
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Owner: mkwst@chromium.org
Hi, thanks for the report. I'm removing the security bug labels since, as you say, we're failing closed.

Mike, could you please take a look?

Comment 2 by est...@chromium.org, Jun 16 2016

Mergedinto: 619603
Status: Duplicate (was: Unconfirmed)
Actually, just realized that this is a duplicate.

Sign in to add a comment