Description
| QPT Data Collection|borderStyle=dashed|borderColor=#cccccc|titleBGColor=#dddddd|bgColor=#e3ffea |
| --- |
|
- QPT release:
1.0.20 - Patch ID
MC-41359 - Are there any additional actions required after the patch installation to make it work?
N/A - Compatible with Magento versions:
Check compatibility
|
Preconditions (*)
On February, 4, Google is set to roll out a new Chrome update that promises a bunch of new features designed to make the browser faster and more secure — including a new approach to cookies.
The SameSite update will require website owners to explicitly state label the third-party cookies that can be used on other sites. Cookies without the proper labelling won’t work in the Chrome browser, which has 63.62% of the overall browser market, according to Statcounter.
Right now, the Chrome SameSite cookie default is: “None,” which allows third-party cookies to track users across sites. But from February, cookies will default into “SameSite=Lax,” which means cookies are only set when the domain in the URL of the browser matches the domain of the cookie — a first-party cookie.
This will not probably affect Magento itself but what about it 3rd party integrations which comes pre installed by default such as NewRelic?
Steps to reproduce (*)
- Open Chrome and go to chrome://flags/
- Enable
SameSite by default cookies
andCookies without SameSite must be secure
- Open the Chrome inspector.
Expected result (*)
- No errors or warnings should show.
Actual result (*)
Admin Panel of a Vanilla Magento 2.3-develop site
Paying with PayPal Express sandbox account
Related links
- https://www.chromestatus.com/feature/5088147346030592
- https://www.troyhunt.com/promiscuous-cookies-and-their-impending-death-via-the-samesite-policy/
- https://tools.ietf.org/html/draft-west-first-party-cookies-07
- https://www.troyhunt.com/promiscuous-cookies-and-their-impending-death-via-the-samesite-policy/
- https://medium.com/adobetech/adobe-experience-cloud-cookie-updates-for-google-chrome-19ad67cf1598
- https://www.netsparker.com/blog/web-security/same-site-cookie-attribute-prevent-cross-site-request-forgery/
- https://blog.chromium.org/2019/10/developers-get-ready-for-new.html
- https://help.salesforce.com/articleView?id=000351874&language=en_US&type=1&mode=1
Metadata
Metadata
Assignees
Labels
Type
Projects
Status