With the latest browsers’ releases we started feeling and hearing more about the SameSite cookie attribute:

This attribute has 3 possible values: Lax, Strict and None. It seems that Lax and Strict work “flawlessly” but there are some issues with None. The reason is that None was introduced after Lax and Strict were implemented and some browsers were not prepared for this.

Here is what happens on incompatible browsers when we have SameSite=None:

  • A cookie is dropped/not created. (that’s kind of scary)
  • A cookie is created as SameSite=Strict.

More details about incompatible browsers:

