on 2020 Jan 31 5:25 AM
Hi all.
We heard that new chrome browser(ver8.0) will be released on Feb 4.
We download Chrome beta and tested our site and found some problem.
User lost hybris JSESSIONID cookie when user returned from the third party site.
New chrome's default cookie policy is SameSite=Lax, not SameSite=None.
So we have to setup JSESSIONID cookie to SameSite=NONE.
Our current Hybris verison is 6.6 and bundled tomcat version is 7.0.82.
Is there any way to setup JSESSIONID to SameSite=None in Tomcat7.0.82?
(I found below link, but it works on over tomcat 8.5.42 only)
https://stackoverflow.com/questions/57505939/how-to-set-samesite-cookie-in-tomcats-cookie-processor
update : I refered below url and added some code to hybris.
https://stackoverflow.com/questions/49697449/how-to-enable-samesite-for-jsessionid-cookie
That made JSESSIONID cookie to SameSite=None successfully in local environment.
But when I applied it to AWS server nothing changed.
How to change JSESSIONID to SameSite=None?
Thanks in advance.
Request clarification before answering.
I answer my own question.
My team colleague solved this problem.
If you are interested in how to solve it, please refer to below.
https://wiki.shibboleth.net/confluence/display/DEV/IdP+SameSite+Filter+Implementation
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi hyunguk_kim
Would you mind sharing the code snippet, because I tried https://stackoverflow.com/questions/49697449/how-to-enable-samesite-for-jsessionid-cookie, but I still cant set the samesite cookie to none/secure. Can you please help me here.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.