how to get chrome to allow cookie in iframe in mvc

Viewed 527

We're running a .net 4.7.2 mvc application which is loaded into a 3rd party web page via an iframe. I've tried setting a cookie as such.

var cookie = new System.Web.HttpCookie("personid", keyid.ToString())
{
    Expires = DateTime.Now.AddYears(1), 
    SameSite = System.Web.SameSiteMode.None, 
    Secure = true
};
Response.Cookies.Set(cookie);

Chrome won't set it even though it should be using the samesite=none, secure code. So then I tried doing it via web.config.

<httpCookies sameSite="None" requireSSL="true" />

Still, the cookie isn't set. I've also tried setting it to Strict, but still no go. My understanding of how it's supposed to work is that in our case, if we have our page being loaded in an iframe from another domain we need to set samesite=none. So, why wouldn't this be working? What else can I try?

I see in firefox that when I use the web.config setting set to Strict, the cookie shows up with the SameSite=Strict setting. However, if I change it to None or set the SameSite to None in the code, nothing shows up at all Thanks.

0 Answers
Related