I am testing a sample widget in my asp.net application. The application sets a cookie called "User" after a successful login.
var Opt = new CookieOptions() { SameSite=SameSiteMode.Lax};
Response.Cookies.Append("User", Input.Email, Opt);
The Widget pages: Index.cshtml.cs:
[AllowAnonymous]
public class IndexModel : PageModel
{
public void OnGet()
{
var User = Request.Cookies["User"];
ViewData["User"] = User;
}
}
Index.cshtml page:
@page
@model Frictionless.Areas.Widget.Pages.IndexModel
@{
}
<div>
<h4>Iframe Content</h4>
<p id="#User">User=@ViewData["User"]</p>
</div>
When I directly access the page: https://localhost:44358/Widget, It correctly shows the User ID. My test HTML that includes iframe from the same page looks like this:
<HTML>
<body>
<div>
<p>This the main page</p>
</div>
<iframe id="FL" src="https://localhost:44358/Widget"></iframe>
</body>
</HTML>
This page shows User=empty. On chrome browser I can clearly see that the cookie is set for this domain, so looks like the browser is for some reason not passing the cookie to the iframe source get. browser page showing iframe and the cookies
I tried various cookie options (httponly, secure, samesite:none, etc.), but none of them helped.