Closed Bug 1622379 Opened 6 years ago Closed 4 years ago

Payments in redsys (iberia.com, tons of spanish websites...) are broken due to sameSite=lax change

Categories

(Core :: Networking: Cookies, defect, P2)

defect

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: emilio, Unassigned)

References

(Blocks 1 open bug)

Details

(Whiteboard: [necko-triaged])

When you execute the order, it says "Session expired", and there's an error in the console like:

Cookie “JSESSIONID” has “sameSite” policy set to “lax” because it is missing a “sameSite” attribute, and “sameSite=lax” is the default value for this attribute.

There's a long redirect chain involved:

And then back in the reverse direction until https://www.service.indra-netplus.com/frontal/preautorizacionSegura/finalizar.html is hit again.

I confirmed that toggling the laxByDefault pref back to false fixes the issue.

STR is trying to book a flight in iberia.com and paying with credit card, fwiw :/

Priority: -- → P2
Whiteboard: [necko-triaged]

Emilio: since this was filed Chrome also shipped this feature (in October 2020). Has redsys fixed their behavior now?

Flags: needinfo?(emilio)

I haven't booked a flight in a while... But let's say it's fixed, since I found a testing store someone has for some sort of woocommerce plugin and I could complete the pay flow with a test account / credit card.

Status: NEW → RESOLVED
Closed: 4 years ago
Flags: needinfo?(emilio)
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.