I can reproduce the issue by following these steps with a website I host:
- Click a link to the website from any external site
- Submit an AJAX form that returns a
Set-Cookieheader with theSameSite=Strictattribute- At this point I can confirm that the cookie is set by looking in
chrome://settings
- At this point I can confirm that the cookie is set by looking in
- Reload the page
On step 3, the cookie is not sent with the request. The devtools network tab shows
The cookie was blocked because it had the "SameSite=Strict" attribute and the request was made from a different site. This includes top-level navigation requests initiated by other sites.
Is this the correct behavior for SameSite=Strict cookies? I understand why the cookie would not be sent with the initial request in step 1 (since it originated from a different site), but I expected that an explicit reload triggered by a user would be considered a same-site request.
