something weird with samesite cookies

79 views Asked by At

If you access to this url from google (you can search it as literally to find it quickly in SERP): https://www.b e b e m o v i l.com/inglesina-electa cookies politic will be shown (blue div) and if press "cerrar" it will make a cookie with flag "1" to prevent showing it again. OK.

That cookie is created with php setcookie as Samesite=Strict and Path /, then inglesina/ subfolder is valid for root path. OK

If , after pressing "Cerrar" button to accept cookies policies, you press F5 to update the page , woalaaa! the message of cookie policies is being shown again (always).

The weird case is that if i access to the same url from adress bar of browser (not from google) , all is working fine, but if i access from google, loop cookie message happens!

Of course if samesite=None it works fine, however i want it is Strict

Any idea please????

1

There are 1 answers

2
Heiko Theißen On

If a website asks users whether they accept tracking cookies and stores the user decision in another cookie, that other cookie should not have SameSite=Strict. Otherwise, the "decision cookie" will be suppressed when the user later navigates to the same site again, and they will be asked whether they accept cookies upon every navigation to it.

Consider complaining to the webmaster of a site that sets "decision cookies" with SameSite=Strict.

SameSite=Strict can be set as a countermeasure against cross-site request forgery (), but it does not distinguish between unwanted effects (navigate to a site and unintentionally transfer money from your bank account) and desirable effects (navigate to a site and let it know that you accept its cookies). See also this question on Security StackExchange.