Bug #78651 [Opn->Csd]: session.cookie_samesite missing the None option

From: Date: Wed, 18 Mar 2020 15:01:45 +0000
Subject: Bug #78651 [Opn->Csd]: session.cookie_samesite missing the None option
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226164@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78651&edit=1 ID: 78651 Updated by: nikic@php.net Reported by: jimmmaaayn at gmail dot com Summary: session.cookie_samesite missing the None option -Status: Open +Status: Closed Type: Bug Package: *General Issues Operating System: All OS's PHP Version: 7.3.10 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: I've added a note to this effect in the php.ini-production/development files with https://github.com/php/php-src/commit/c00cce3229515eacdb1680f39132ed3ca09cc205. With that, I consider this resolved, as this is already working fine if you do it right... Previous Comments: ------------------------------------------------------------------------ [2020-03-18 14:55:21] nikic@php.net I think I get it... Contrary to the given test script, you presumably have something like session.cookie_samesite=None in your php.ini. However, "none" is a special value in ini files, and what you want is session.cooke_samesite="None" ------------------------------------------------------------------------ [2020-03-18 14:52:48] nikic@php.net > cat t048.php <?php ini_set('session.cookie_samesite','None'); session_start(); > sapi/cgi/php-cgi t048.php X-Powered-By: PHP/7.3.16-dev Set-Cookie: PHPSESSID=e7c6bf56463ebb1eaf0dfdd0a8e2257d; path=/; SameSite=None Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-type: text/html; charset=UTF-8 Seems to work fine already? Nothing in PHP checks whether the value of cookie_samesite is actually valid, you can put whatever in it. ------------------------------------------------------------------------ [2020-03-17 22:48:12] marco dot marsala at live dot it A simple workaround is: session_set_cookie_params([‘samesite’ => ‘None’]); ------------------------------------------------------------------------ [2019-12-10 11:27:21] tom at peopleperhour dot com This issue is very important - all hell will break loose come Feb/2020 when Google Chrome default the SameSite cookie attribute to Lax if we cannot set the PHP session cookie back to None. For example, it will be important for any sites that have Payment Gateways where the users are sent off to the Payment processor site, then POSTed back after the payment. Sites will find their users are no longer logged-in when they return. I can't overstate how important it is that this issue is fixed before Google Chrome change their default behaviour (currently due Feb/2020, source: https://blog.chromium.org/2019/10/developers-get-ready-for-new.html ) ------------------------------------------------------------------------ [2019-10-09 00:06:00] jimmmaaayn at gmail dot com Description: ------------ Setting session.cookie_samesite=None in php ini does not set attribute of session samesite to None in order for it to work on third party sites in the future. Browsers like Chrome are forcing no specified samesite to be default Lax instead of None. See https://www.chromium.org/updates/same-site Also Note down that None requires secure cookie for chrome by 2020 Test script: --------------- ini_set('session.cookie_samesite','None');session_start(); Expected result: ---------------- Session cookie should be set with the SameSite None attribute Actual result: -------------- Session cookie is not set with any Samesite Attribute ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78651&edit=1

« previous php.bugs (#226164) next »