Bug #78651 [Opn->Csd]: session.cookie_samesite missing the None option
| From: | nikic@php.net | Date: | Wed, 18 Mar 2020 15:01:45 +0000 |
| Subject: | Bug #78651 [Opn->Csd]: session.cookie_samesite missing the None option | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226164@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78651&edit=1
ID: 78651
Updated by: nikic@php.net
Reported by: jimmmaaayn at gmail dot com
Summary: session.cookie_samesite missing the None option
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: All OS's
PHP Version: 7.3.10
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
I've added a note to this effect in the php.ini-production/development files with https://github.com/php/php-src/commit/c00cce3229515eacdb1680f39132ed3ca09cc205.
With that, I consider this resolved, as this is already working fine if you do it right...
Previous Comments:
------------------------------------------------------------------------
[2020-03-18 14:55:21] nikic@php.net
I think I get it... Contrary to the given test script, you presumably have something like
session.cookie_samesite=None
in your php.ini. However, "none" is a special value in ini files, and what you want is
session.cooke_samesite="None"
------------------------------------------------------------------------
[2020-03-18 14:52:48] nikic@php.net
> cat t048.php
<?php
ini_set('session.cookie_samesite','None');
session_start();
> sapi/cgi/php-cgi t048.php
X-Powered-By: PHP/7.3.16-dev
Set-Cookie: PHPSESSID=e7c6bf56463ebb1eaf0dfdd0a8e2257d; path=/; SameSite=None
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Content-type: text/html; charset=UTF-8
Seems to work fine already?
Nothing in PHP checks whether the value of cookie_samesite is actually valid, you can put whatever
in it.
------------------------------------------------------------------------
[2020-03-17 22:48:12] marco dot marsala at live dot it
A simple workaround is:
session_set_cookie_params([âsamesiteâ => âNoneâ]);
------------------------------------------------------------------------
[2019-12-10 11:27:21] tom at peopleperhour dot com
This issue is very important - all hell will break loose come Feb/2020 when Google Chrome default
the SameSite cookie attribute to Lax if we cannot set the PHP session cookie back to None. For
example, it will be important for any sites that have Payment Gateways where the users are sent off
to the Payment processor site, then POSTed back after the payment. Sites will find their users are
no longer logged-in when they return.
I can't overstate how important it is that this issue is fixed before Google Chrome change
their default behaviour (currently due Feb/2020, source: https://blog.chromium.org/2019/10/developers-get-ready-for-new.html
)
------------------------------------------------------------------------
[2019-10-09 00:06:00] jimmmaaayn at gmail dot com
Description:
------------
Setting session.cookie_samesite=None in php ini does not set attribute of session samesite to None
in order for it to work on third party sites in the future. Browsers like Chrome are forcing no
specified samesite to be default Lax instead of None. See https://www.chromium.org/updates/same-site
Also Note down that None requires secure cookie for chrome by 2020
Test script:
---------------
ini_set('session.cookie_samesite','None');session_start();
Expected result:
----------------
Session cookie should be set with the SameSite None attribute
Actual result:
--------------
Session cookie is not set with any Samesite Attribute
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78651&edit=1