Django session cookie forgotten on every browser reopen - mobile Safari (iphone,ipad)

Viewed 283

I wonder if anybody encountered with this problem. I am storing some data about visitor in django session. It works as expected but only mobile safari (iphone and ipad) have strange behaviour. When I visit my site from iphone or ipad(Safari ver. 14.3) session cookie is normally set. But when I close the browser then reopen, new session cookie is generated. This behaviour can be seen only on mobile safari version. I was not able to reproduce it on macOS desktop safari.

To solve this problem I had to change setup for session cookie in django settings.py:

SESSION_COOKIE_SAMESITE = ‘None’

According to django doc. cookie is normally set as ‘lax’ and this introduce security risk in my app.

SESSION_COOKIE_SAMESITE

Default: 'Lax' The value of the SameSite flag on the session cookie. This flag prevents the cookie from being sent in cross-site requests thus preventing CSRF attacks and making some methods of stealing session cookie impossible. Possible values for the setting are:

  • 'Strict': prevents the cookie from being sent by the browser to the target site in all cross-site browsing context, even when following a regular link. 
For example, for a GitHub-like website this would mean that if a logged-in user follows a link to a private GitHub project posted on a corporate discussion forum or email, GitHub will not receive the session cookie and the user won’t be able to access the project. A bank website, however, most likely doesn’t want to allow any transactional pages to be linked from external sites so the 'Strict' flag would be appropriate.
  • 'Lax' (default): provides a balance between security and usability for websites that want to maintain user’s logged-in session after the user arrives from an external link. 
In the GitHub scenario, the session cookie would be allowed when following a regular link from an external website and be blocked in CSRF-prone request methods (e.g. POST).
  • 'None' (string): the session cookie will be sent with all same-site and cross-site requests.
  • False: disables the flag.


I guess that I had to cause security hole in my django app intentionally. I don’t like it but I am not sure how serious risk it is. I would love to know why only mobile safari behave like that.

0 Answers
Related