Payments in redsys (iberia.com, tons of spanish websites...) are broken due to sameSite=lax change
Categories
(Core :: Networking: Cookies, defect, P2)
Tracking
()
People
(Reporter: emilio, Unassigned)
References
(Blocks 1 open bug)
Details
(Whiteboard: [necko-triaged])
When you execute the order, it says "Session expired", and there's an error in the console like:
Cookie “JSESSIONID” has “sameSite” policy set to “lax” because it is missing a “sameSite” attribute, and “sameSite=lax” is the default value for this attribute.
There's a long redirect chain involved:
| Reporter | ||
Comment 1•6 years ago
|
||
And then back in the reverse direction until https://www.service.indra-netplus.com/frontal/preautorizacionSegura/finalizar.html is hit again.
| Reporter | ||
Comment 2•6 years ago
|
||
I confirmed that toggling the laxByDefault pref back to false fixes the issue.
| Reporter | ||
Comment 3•6 years ago
|
||
STR is trying to book a flight in iberia.com and paying with credit card, fwiw :/
Updated•6 years ago
|
Comment 4•4 years ago
|
||
Emilio: since this was filed Chrome also shipped this feature (in October 2020). Has redsys fixed their behavior now?
| Reporter | ||
Comment 5•4 years ago
|
||
I haven't booked a flight in a while... But let's say it's fixed, since I found a testing store someone has for some sort of woocommerce plugin and I could complete the pay flow with a test account / credit card.
Description
•