Cookies are not being set into deployed website while using ASP.NET framework 4.6.1 and Chrome

Viewed 177

Httpcookie is not being set in Chrome. It's working as expected in the Mozilla browser. We are using .NET framework 4.6.1.

We wrote the following rewrite rule in web.config:

<rewrite>
  <outboundRules>
    <rule name="Add SameSite" preCondition="Lax SameSite">
      <match serverVariable="RESPONSE_Set_Cookie" pattern=".*" negate="false" />
      <action type="Rewrite" value="{R:0}; SameSite=Lax" />
      <conditions>
      </conditions>
    </rule>
    <preConditions>
      <preCondition name="Lax SameSite">
        <add input="{RESPONSE_Set_Cookie}" pattern="." />
        <add input="{RESPONSE_Set_Cookie}" pattern="; SameSite=Lax" negate="true" />
      </preCondition>
    </preConditions>
  </outboundRules>
</rewrite>

We are using following code to set cookie

public void Set(string key, string value, int expireHours = 1)
{
    HttpCookie cookie = HttpContext.Current.Request.Cookies[Constants.CookieName];

    if (cookie == null)
        cookie = new HttpCookie(Constants.CookieName);

    cookie.Secure = true;
    cookie.Expires = DateTime.Now.AddHours(expireHours);
    cookie[key] = value;

    HttpContext.Current.Response.Cookies.Add(cookie);
}

However, if I set to Secure attribute to false for localhost it's working fine.As our website is hosted on HTTPS so i added cookie.Secure = true; though, This is not working into the chrome browser.We can not update the ASP.NET framework right now.

Any help would be appreciated.Thank you.

0 Answers
Related