The IT department at the company I work for has recently upgraded me to Chrome 91.0.4472.124, and now I am having a problem with an application I'm responsible for.
3rd-party cookies are not being included in cross-domain requests, despite having correct SameSite settings - here is the entire cookie:
JSESSIONID=F4C3A14243123754355B3A6645AFFECD; Max-Age=43200; Expires=Sun, 04-Jul-2021 05:54:55 GMT; Path=/; Secure; HttpOnly; SameSite=None
I've captured the following NetLog trace (actual urls redacted) using chrome's NetLog tool and can see a 'DO_NOT_SAVE_COOKIES' flag being set for my cross-site requests:
=15002 [st= 0] +REQUEST_ALIVE [dt=28]
--> priority = "MEDIUM"
--> traffic_annotation = 101845102
--> url = "https://<siteA><url>"
t=15002 [st= 0] NETWORK_DELEGATE_BEFORE_URL_REQUEST [dt=0]
t=15002 [st= 0] +URL_REQUEST_START_JOB [dt=27]
--> initiator = "https://<siteB>"
--> load_flags = 16448 (DO_NOT_SAVE_COOKIES | SUPPORT_ASYNC_REVALIDATION)
--> method = "GET"
--> network_isolation_key = "https://<domain> https://<domain>"
--> privacy_mode = "enabled"
--> request_type = "other"
--> site_for_cookies = "SiteForCookies: {site=https://<domain>; schemefully_same=true}"
--> url = "https://<siteA><url>"
Why is DO_NOT_SAVE_COOKIES being set? Is that why cookies are not being included in requests?