cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Is there any way to setup JSESSIONID to SameSite=None in Tomcat7.0.82?

15,053

Hi all.

We heard that new chrome browser(ver8.0) will be released on Feb 4.

We download Chrome beta and tested our site and found some problem.

User lost hybris JSESSIONID cookie when user returned from the third party site.

New chrome's default cookie policy is SameSite=Lax, not SameSite=None.

So we have to setup JSESSIONID cookie to SameSite=NONE.

Our current Hybris verison is 6.6 and bundled tomcat version is 7.0.82.

Is there any way to setup JSESSIONID to SameSite=None in Tomcat7.0.82?

(I found below link, but it works on over tomcat 8.5.42 only)

https://stackoverflow.com/questions/57505939/how-to-set-samesite-cookie-in-tomcats-cookie-processor

update : I refered below url and added some code to hybris.

https://stackoverflow.com/questions/49697449/how-to-enable-samesite-for-jsessionid-cookie

That made JSESSIONID cookie to SameSite=None successfully in local environment.

But when I applied it to AWS server nothing changed.

How to change JSESSIONID to SameSite=None?

Thanks in advance.

Accepted Solutions (0)

Answers (1)

Answers (1)

I answer my own question.

My team colleague solved this problem.

If you are interested in how to solve it, please refer to below.

https://wiki.shibboleth.net/confluence/display/DEV/IdP+SameSite+Filter+Implementation

0 Kudos

Hi hyunguk_kim

Would you mind sharing the code snippet, because I tried https://stackoverflow.com/questions/49697449/how-to-enable-samesite-for-jsessionid-cookie, but I still cant set the samesite cookie to none/secure. Can you please help me here.