<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 2/6/20 6:50 PM, Cantor, Scott wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CY4PR0101MB309613953FA3FEB62D1BA4C8D01D0@CY4PR0101MB3096.prod.exchangelabs.com">
      <pre class="moz-quote-pre" wrap="">
Yes, that's certainly odd. Any evidence they're only setting SameSite for Chrome? I didn't trace it to check.
</pre>
    </blockquote>
    <p><br>
    </p>
    <p>I thought you were onto something with that.  SameSite is not
      being set for FF.  But then I looked and it's (now) not being set
      for Chrome either.  I could have *sworn* in my earlier tests it
      was being set to None for their main 'canvas_session' cookie.  But
      it's not now for me.  To confuse matters further, it still works
      in Chrome with the flags set and the lack of a SameSite (!!!!!). 
      I tried 3 times, clearing state and restarting, trying to
      eliminate user error.  Maybe I am doing something wrong.  Or maybe
      the Canvas infrastructure is not consistently updated in the AWS
      environment, and it's depending on which random node I'm hitting,
      or something.  I'll try again later.<br>
    </p>
    <p>Anyway... I'm extremely confused now.  Is there an emoji for
      pulling one's hair out?<br>
    </p>
  </body>
</html>