<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Scott,</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
This update is timely!  Yesterday I and others observed IdP session loss during cross-domain (non-wisc.edu) SSO HTTP-POST requests to our IdP, despite having htmlLocalStorage enabled and using ClientSessionStorageService.</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I just want to verify that the "do nothing" option is still viable, perhaps I missed a setting?</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
For now I'm adding "; SameSite=None" to non-SameSite-annotated cookies when the user agent is Chrome / Chromium 80+ and Firefox 79+, which seems to have stemmed the bleeding.</div>
<div id="appendonsend"></div>
<div style="font-family:Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thanks!</div>
<div style="font-family:Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Ryan</div>
<div style="font-family:Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Thursday, August 13, 2020 14:39<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Bit of a SameSite update</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">And...Firefox.<br>
<br>
<a href="https://hacks.mozilla.org/2020/08/changes-to-samesite-cookie-behavior/">https://hacks.mozilla.org/2020/08/changes-to-samesite-cookie-behavior/</a><br>
<br>
Will update the page with that.<br>
<br>
-- Scott<br>
<br>
On 8/13/20, 3:35 PM, "users on behalf of Cantor, Scott" <users-bounces@shibboleth.net on behalf of cantor.2@osu.edu> wrote:<br>
<br>
    I've been adjusting the page intro [1] a bit to reflect the fact that Chrome's breaking change has been rolling out for the last month, and will also be breaking Edge shortly.<br>
<br>
    I also finally hit an SP behaving so pathologically broken with frames and POST such that third-party cookies alone weren't enough and the SameSite change broke the IdP.<br>
<br>
    So it's starting to get real, just thought I'd note it.<br>
<br>
    -- Scott<br>
<br>
    [1] <a href="https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/display/IDP4/SameSite__;!!KGKeukY!n9UZ6SSSEj89s2VtXKSEWOZ1MFTWDXlKwJtcLpFGt5Ps1CCywxXb2m9CX9zIy8g$">
https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/display/IDP4/SameSite__;!!KGKeukY!n9UZ6SSSEj89s2VtXKSEWOZ1MFTWDXlKwJtcLpFGt5Ps1CCywxXb2m9CX9zIy8g$</a>
<br>
<br>
    -- <br>
    For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!KGKeukY!n9UZ6SSSEj89s2VtXKSEWOZ1MFTWDXlKwJtcLpFGt5Ps1CCywxXb2m9C5Ww0mnw$">
https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!KGKeukY!n9UZ6SSSEj89s2VtXKSEWOZ1MFTWDXlKwJtcLpFGt5Ps1CCywxXb2m9C5Ww0mnw$</a>
<br>
    To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>