I'm developing an IdP with IdentityServer4, and everything works fine, but now from the security perspective, I want to make it as secure as I can; So I made all cookies SameSite as Strict, and after that, I got HTTP error code 400 in situation below:
- User
TestUseropens the client appA TestUsersigned in to the client appATestUsersigned out from the client appATestUseris trying to log into the client appAagain (he/she hits the login button in the client appA)- at this point, the
TestUserredirects to myIdP's login page but receives only theHTTP 400 error codeand no other details are displayed to check the status.
And my configuration:
// Identity Cookie (Authentication cookie)
services.ConfigureApplicationCookie(options =>
{
// options.Cookie.Name = .....
options.Cookie.HttpOnly = true;
options.Cookie.SecurePolicy = CookieSecurePolicy.Always;
options.Cookie.SameSite = SameSiteMode.Strict; // <<<<<<<<<<<<<<<<<<<<<<<
options.SlidingExpiration = false;
// without expire time ~> session cookie. destroy after closing the browser
// options.ExpireTimeSpan = TimeSpan.FromSeconds(10000);
// options.Cookie.Expiration = TimeSpan.FromSeconds(1000);
});
And as you can see, .AspNetCore.Identity.Application (application cookie) cookie is set to be SameSite=Strict. If the SameSite set to be Lax, everything works fine, but what is the matter with SameSite=Strictin this scenario?
