New issue
Advanced search Search tips

Issue 895939 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 871998
Owner: ----
Closed: Oct 19
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Dev Tools Network Tab creates request without Cookie header

Reported by ben.p...@openreign.com, Oct 16

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36

Steps to reproduce the problem:
I have a website that sets the src of an img and then quickly changes it. This (appropriately causes Chrome to cancel the request to the first src). 

However, if the Chrome Dev Tools are open to the Network tab, an additional request is made the original (cancelled) URL. I think this is to so an icon thumbnail of the image. But this request does not contain the cookie HTTP header, causing the server to generate an new session cookie. And Chrome stores this cookie, destroying the users original session.

I've attached a simple server that can be run with node.js to demonstrate the problem.

What is the expected behavior?
No side effects from using Dev Tools.

What went wrong?
Dev Tools should not have side effects, like creating additional requests. If Dev Tools must create a request, it should send the cookies.

Did this work before? N/A 

Chrome version: 69.0.3497.100  Channel: stable
OS Version: 10.0
Flash Version: 

The behavior is not totally reliable. Sometimes the additional request contains the headers. Sometimes Chrome keeps both the original session cookie and the new one. Then subsequent request would have two cookie headers.
 
test.js
2.1 KB View Download
Components: Platform>DevTools
Is the cookie included if you don't use the SameSite=lax header?  If so, this is likely a dupe of  issue 871998 .
Samesite-lax cookie property, rather.
No. I removed all cookie properties and the behavior is the same.
Actually, I neglected to clear the original session cookie. Removing the property fixed it.
Labels: Needs-Triage-M69
Cc: susan.boorgula@chromium.org
Labels: Triaged-ET Needs-Feedback
ben.page@ Thanks for the update.

As per comment #4, as the issue is fixed by clearing the cookies, can you please confirm if this issue can be closed?

Thanks..
This is indeed a duplicate of  issue 871998  and can be closed.
Project Member

Comment 8 by sheriffbot@chromium.org, Oct 17

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Mergedinto: 871998
Status: Duplicate (was: Unconfirmed)

Sign in to add a comment