Bug #78651 [Com]: session.cookie_samesite missing the None option
| From: | tom at peopleperhour dot com | Date: | Tue, 10 Dec 2019 11:27:21 +0000 |
| Subject: | Bug #78651 [Com]: session.cookie_samesite missing the None option | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224184@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78651&edit=1
ID: 78651
Comment by: tom at peopleperhour dot com
Reported by: jimmmaaayn at gmail dot com
Summary: session.cookie_samesite missing the None option
Status: Open
Type: Bug
Package: *General Issues
Operating System: All OS's
PHP Version: 7.3.10
Block user comment: N
Private report: N
New Comment:
This issue is very important - all hell will break loose come Feb/2020 when Google Chrome default
the SameSite cookie attribute to Lax if we cannot set the PHP session cookie back to None. For
example, it will be important for any sites that have Payment Gateways where the users are sent off
to the Payment processor site, then POSTed back after the payment. Sites will find their users are
no longer logged-in when they return.
I can't overstate how important it is that this issue is fixed before Google Chrome change
their default behaviour (currently due Feb/2020, source: https://blog.chromium.org/2019/10/developers-get-ready-for-new.html
)
Previous Comments:
------------------------------------------------------------------------
[2019-10-09 00:06:00] jimmmaaayn at gmail dot com
Description:
------------
Setting session.cookie_samesite=None in php ini does not set attribute of session samesite to None
in order for it to work on third party sites in the future. Browsers like Chrome are forcing no
specified samesite to be default Lax instead of None. See https://www.chromium.org/updates/same-site
Also Note down that None requires secure cookie for chrome by 2020
Test script:
---------------
ini_set('session.cookie_samesite','None');session_start();
Expected result:
----------------
Session cookie should be set with the SameSite None attribute
Actual result:
--------------
Session cookie is not set with any Samesite Attribute
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78651&edit=1