Web server cookie changes not working from iframe in Chrome with SameSite=None

Viewed 369

I have a web app that is used in an iframe (it is a Word Office add-in).

The iframe app has a simple logout link (e.g., https://www.example.com/logout) to clear the session cookie. This logout link:

  • works outside of the iframe in all browsers
  • works in the iframe in Safari and Firefox, but
  • doesn't work in the iframe in Chrome even though I've set SameSite=None.

My session cookie has the following settings:

  • Not permanent (though lasts a long time)
  • SameSite=None
  • Secure
  • HttpOnly
  • Domain is example.com instead of www.example.com but I don't think this is the issue

Here is a screenshot in case you don't believe me :): enter image description here

Googling for this returns a ton of hits recommending to set SameSite=None but I've already done that.

Any idea why the web server can't change the cookie from the iframe?

0 Answers
Related