<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p><br>
</p>
<div class="moz-cite-prefix">On 2/6/20 6:50 PM, Cantor, Scott wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CY4PR0101MB309613953FA3FEB62D1BA4C8D01D0@CY4PR0101MB3096.prod.exchangelabs.com">
<pre class="moz-quote-pre" wrap="">
Yes, that's certainly odd. Any evidence they're only setting SameSite for Chrome? I didn't trace it to check.
</pre>
</blockquote>
<p><br>
</p>
<p>I thought you were onto something with that. SameSite is not
being set for FF. But then I looked and it's (now) not being set
for Chrome either. I could have *sworn* in my earlier tests it
was being set to None for their main 'canvas_session' cookie. But
it's not now for me. To confuse matters further, it still works
in Chrome with the flags set and the lack of a SameSite (!!!!!).
I tried 3 times, clearing state and restarting, trying to
eliminate user error. Maybe I am doing something wrong. Or maybe
the Canvas infrastructure is not consistently updated in the AWS
environment, and it's depending on which random node I'm hitting,
or something. I'll try again later.<br>
</p>
<p>Anyway... I'm extremely confused now. Is there an emoji for
pulling one's hair out?<br>
</p>
</body>
</html>