Open Bug 1618610 (sameSiteLax-breakage) Opened 5 years ago Updated 1 month ago

[meta] breakage for cookie sameSite=lax by default

Categories

(Core :: Networking: Cookies, task, P3)

task

Tracking

()

REOPENED

People

(Reporter: baku, Unassigned)

References

Details

(Keywords: meta, Whiteboard: [necko-triaged])

Attachments

(1 file)

Site breakage as a result of cookie sameSite=lax by default.

Priority: -- → P2
See Also: → samesitelax

Nhi, what's the preferred workflow when we find regressions related to SameSite=Lax? Should we be doing outreach, or asking folks to do some analysis?

Flags: needinfo?(nhnguyen)
Depends on: 1620179
Depends on: 1620018

For regressions related to samesite=lax, my preference is to do outreach, as sites may not be aware of this change (or that they are relying on the default behaviour)

Flags: needinfo?(nhnguyen)
Whiteboard: [necko-triaged]

I cannot login to this site with Nightly 76.0a1 (2020-03-09) (64-bit).

https://jp.finalfantasyxiv.com/lodestone/
(Online game users site)

There is no problem with Firefox 73.0.1 or Google Chrome 80.0.3987.132.

And, I can login with Nightly that network.cookie.sameSite.laxByDefault changed tofalse.

I want to you block this change.

Depends on: 1620547

(In reply to robert from comment #3)

I cannot login to this site with Nightly 76.0a1 (2020-03-09) (64-bit).

https://jp.finalfantasyxiv.com/lodestone/
(Online game users site)

There is no problem with Firefox 73.0.1 or Google Chrome 80.0.3987.132.

And, I can login with Nightly that network.cookie.sameSite.laxByDefault changed tofalse.

I want to you block this change.

Can you file a new bug please? Eventually that site will stop working in Chrome 80 (and it's possible it doesn't work for others now, they're still rolling out the change).

Flags: needinfo?(robert)
Blocks: 1619972
Blocks: 1620104
Depends on: 1618336

Hi,

When setting SameSite=None for a cookie, Firefox v 73.0.1 treats it as unset. Can you please confirm that Samesite=None is supported on Firefox and confirm this bug?

I don't understand the question. Since Firefox 73 didn't enable sameSite=lax by default, sameSite=None is the same as unset. Did you flip network.cookie.sameSite.laxByDefault on your own? It is an unsupported configuration. Moreover, Firefox 73 itself is no longer supported.

In any case, please file a new bug and block this bug instead of commenting on a meta bug.

(In reply to Masatoshi Kimura [:emk] from comment #6)

I don't understand the question. Since Firefox 73 didn't enable sameSite=lax by default, sameSite=None is the same as unset. Did you flip network.cookie.sameSite.laxByDefault on your own? It is an unsupported configuration. Moreover, Firefox 73 itself is no longer supported.

In any case, please file a new bug and block this bug instead of commenting on a meta bug.

Elaborated here: https://bugzilla.mozilla.org/show_bug.cgi?id=1623783

See Also: → 1623949

Bug 1620179 fixed my issue with HBOGo.com. I set the prefs in question back to their true default and I can now log into my ISP and stream videos. History.com while displaying a similar problem with logging into my ISP the fix did not help. It might be a problem with history.com itself. I reported it to the tech people over at history.com.

Since our implementation had a bug (bug 1620179), blocking bugs and webcompat issues should check whether the site is still broken with the latest Nightly.

(In reply to Masatoshi Kimura [:emk] from comment #9)

Since our implementation had a bug (bug 1620179), blocking bugs and webcompat issues should check whether the site is still broken with the latest Nightly.

Not sure if this was directed a me or not. I am on the latest Nightly Fx76 which of course has bug 1620179 incorporated into it.

Sorry, it is not directed you. It is a general announcement that every subscriber should aware.

Depends on: 1626696
Regressions: 1622276
Depends on: 1622276
No longer regressions: 1622276
No longer blocks: 1619972, 1620104
Depends on: 1619972, 1620104
Depends on: 1628083
Depends on: 1634921
Depends on: 1642832
Depends on: 1648971
Alias: sameSiteLax-breakage
Depends on: 1652815
Depends on: 1653188
Depends on: 1664709
Depends on: 1680382
Severity: normal → N/A
Priority: P2 → P3
Webcompat Priority: --- → ?
Depends on: 1732444
Depends on: 1578068
Depends on: 1737460
Webcompat Priority: ? → ---
Depends on: 1681856
Depends on: 1743003
Depends on: 1530995
Depends on: 1665794
Depends on: 1742600
Depends on: 1679318
Depends on: 1714542
See Also: → 1653518
No longer blocks: samesitelax

A family member was unable to create a Schwab brokerage account via https://onboard.schwab.com on Mac desktop. They ended up switching to Schwab's mobile app, which worked fine.
I tested it in Firefox on desktop, and found that it didn't work for me either, until I added the following cookie exceptions:
https://www.schwab.com
https://sws-gateway.schwab.com

@Kathleen This is a meta bug. Could you please file a new bug and add a dependency?

Flags: needinfo?(kwilson)
Depends on: 1748100

Done. Thanks.

Flags: needinfo?(kwilson)
See Also: 1623949
No longer depends on: 1604212
No longer depends on: 1743003
Depends on: 1748577
No longer depends on: 1748100
Depends on: 1749634
Depends on: 1750152
Depends on: 1751191
Depends on: 1753918
Depends on: 1761106
Depends on: 1753874
No longer depends on: 1753874
Depends on: 1674724
See Also: → 1749679

Redirect a needinfo that is pending on an inactive user to the triage owner.
:dragana, since the bug has recent activity, could you have a look please?

For more information, please visit auto_nag documentation.

Flags: needinfo?(robert) → needinfo?(dd.mozilla)
Flags: needinfo?(dd.mozilla)
Depends on: 1787206
Depends on: 1794623
See Also: samesitelax
Type: defect → task

We won't be shipping samesitelax by default, so all of this breakage bugs can also be closed.

Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → WONTFIX

Reopening because having a different default than Chrome is starting to cause webcompat problems. e.g. bug 1987563

Status: RESOLVED → REOPENED
Resolution: WONTFIX → ---
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: