RSS Feed/News Is There Still a Reason to Not Use SameSite Strict or Lax for Cookies?

Status
Not open for further replies.

ENXF NET

Administrator
Staff member
Administrator
Moderator
+Lifetime VIP+
S.V.I.P.S Member
S.V.I.P Member
V.I.P Member
Collaborate
Registered
Joined
Nov 13, 2018
Messages
23,698
Points
823

Reputation:

I've put $config['cookie']['samesite'] = 'Strict'; into my config.php, deleted my cookies and verified their SameSite attribute are set to Strict.

Then I tried accessing my forum from a link on social media.

I also tried registering using a social media account and logging in.

Everything seems to work flawlessly and I'm still logged in even though technically in Strict mode, cookies aren't sent with the initial request to the forum from other websites unlike Lax. Im assuming...

Read more

Continue reading...
 
Status
Not open for further replies.
Top