3 ms·
The article recommends setting network.cookie.sameSite.noneRequiresSecure to true - this sounds like it would ignore the https only flag (on cookies that set it
by snomad 6y ago
The article recommends setting network.cookie.sameSite.noneRequiresSecure to true - this sounds like it would ignore the https only flag (on cookies that set it)?
Is samesite=lax, cookie = https only not a valid config?
- wccrawford 6y agoThey recommend that if you want to try what will be the defaults when they release this. The other setting is the other half of it. If you enable only the setting you specified, you won't be able to set samesite=none on http cookies, only "secure" cookies for https-only. If you enable the other setting, cookies will default to Lax, regardless of "secure" status for the cookie. If you enable both, the only way to have a samesite=None (totally insecure) cookie is over https and by manually specifying None.