Issue metadata
Sign in to add a comment
|
[Play Stable] Users can not make payment on 11st.co.kr |
||||||||||||||||||||||||||
Issue descriptionChrome Version: 63.0.3239.83 OS: Android What steps will reproduce the problem? Since Dec 9, Korean users can not make a payment in Chrome when they check out in 11st.co.kr which is a big/popular shopping website in Korea. Users say they were asked to allow cookies when trying to make the payment but after they went to Chrome setting to allow cookies, they still couldn't make the payment. Play review: https://listnr.corp.google.com/product/282/reports?filter=0&dateRange=30&sources=8590027391&versions=63.0.3239.83&countries=KR In-app feedback: https://listnr.corp.google.com/product/282/reports?searchText=payment&filter=0&dateRange=30&sources=8590013633&versions=63.0.3239.83&countries=KR
,
Dec 11 2017
,
Dec 11 2017
rouslan@, thanks for the prompt response. Unfortunately none of the feedback report we've received mention "your connection is not secure". A lot of users said they were asked to allow Cookies. Will Chrome ask users to allow cookies if chrome considers the website's connection is not secure? Thanks.
,
Dec 11 2017
Device: Samsung Galaxy S8/NRD90M Chrome version: 63.03239.83 Web site: http://global.11st.co.kr/html/en/main_en.html Result: Was able to purchase and check out item from the web site. No issues were found.
,
Dec 11 2017
I'm reaching out to users on Play store and through email for steps to reproduce this issue. Will update the bug once I hear anything. Thanks.
,
Dec 11 2017
Thanks Robert!
,
Dec 12 2017
Can anyone own this bug and look into it? rouslan@ ?
,
Dec 12 2017
> Will Chrome ask users to allow cookies if chrome considers the website's connection is not secure? Nope, that's not Chrome doing that, AFAIK.
,
Dec 12 2017
One user said he saw "A001 it is recommended to set the browser cookie to always allowed when repeating the same error" (screenshot as attached) when he click "안심클릭" (a 3rd party credit card payment security verification) when he try to pay online. Here is the translated message from this user: "i can not proceed with credit card payment on Chrome ver. 63. the affected cards are Samsung, Hyundai, Nonghyup, Shinhan etc, the ones with 안심클릭 (safe click) verification. i checked with the card companies and was told it's due to Chrome ver. 63 issue. please fix this asap"
,
Dec 12 2017
Which Chrome ver. 63 issue, though? 😕
,
Dec 13 2017
The user feedback report in the original post has ver 63.0.3239.83 (Android)
,
Dec 13 2017
I work for a credit card company in Korea. As you know, many errors have occurred since the software was updated, we are aware of the cause. According to the problems we have found, Customers using version 63 of Chrome have confirmed that cookie information is not being delivered properly with "iframe" function. Because many e-commerce sites in Korea handle transactions using third party cookies, this is a problem. The error message shown to the customer is what the customer can understand and is different from the actual cause. I would like to inquire if you can confirm the contents below. Since version 63 of Chrome (Android), 1) Has the default setting for third party cookies changed in the WebView Toolkit? For example, if the app developer does not set "setThirdPatyCookies" value, will this be false or not? 2) If the customer has thirdpartycookies set to true in their Chrome settings, does that apply to false if we do not specify them separately in webkit? 3) Are these policies still maintained after 64?
,
Dec 13 2017
"deux...@gmail.com"'s questions are very good, is there someone from Google can confirm about this bug existence ? at least we need to get yes/no confirmation because we have tried anything we can and we are under pressure to solve this problem within our app which we still have not found the work-around it.
,
Dec 13 2017
rouslan@, Korean team has filed b/70481162 for this issue this Monday. I've cc'ed you in that bug. Thanks.
,
Dec 13 2017
mkwst@: Any idea if we've changed anything regarding third party cookies in M63? Non-Google people: Would it be possible to get a simple test case we can use to reproduce the issue? For example a small standalone web page, or a link that doesn't require us to try to buy things.
,
Dec 13 2017
If this is WebView-related, it might be https://crbug.com/793648 , which clamy@ landed a patch to fix last night and merged back to 64 and 63.
,
Dec 13 2017
timloh@: I've seen same issue occurs not only Korea but also in other services. For example, you can check out the stackoverflow website for more details on the same issue and sample code to identify issues related to cookies. https://stackoverflow.com/questions/47731745/android-cordova-app-with-iframes-chrome-63-no-request-headers-cookies If you want to have exactly the same test that Koreans are experiencing regard to this issue, we will send you a test guide including the card number issued in Korea.
,
Dec 13 2017
From what I read in the report, this is WebView specific and the website is working fine on Chrome browser. I'm pretty sure that this is a duplicate of https://crbug.com/793648 which was reported for cordova. We fixed the cordova issue yesterday, and it was merged to M63 so the problem should be resolved soon. I will mark this as a duplicate.
,
Dec 13 2017
Thank you, Camille!
,
Dec 14 2017
Chrome last version (63.0.3239.107) still has an iframe cookie issue in webview.
,
Dec 15 2017
I work at GSSHOP(http://www.gsshop.com) test team. We found this issue(chrome browser ver. 63.0.3239.83 on android )on December 9th. Test team reproduced this issue and reported development team. We solved by replacing the certificate and the KMC(://www.kmcert.com) module. I hope my comments will be helpful to other Korean eCommerce companies and Google. We also check chrome browser ver. 63.0.3239.107. Our app had no issues. |
|||||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||||
Comment 1 by rouslan@chromium.org
, Dec 11 2017Components: -Blink>Payments UI>Browser>Omnibox>SecurityIndicators UI>Browser>Autofill
56.4 KB
56.4 KB View Download