3

As some of you know, Chrome will start using a new SameSite cookie policy this month (https://web.dev/samesite-cookies-explained/ and https://www.chromium.org/updates/same-site).

We are using Auth0 for our App and have seen this SameCookie warning in Chrome's console since the end of last year:

enter image description here

Now since introduction of the new policy is getting closer, I tried to find the offending cookie using the Application view in Chrome's developer tools. This is what is shows:

enter image description here

As you can see, there is no entry for Secure or SameSize for any cookie.

So I enabled the new policy to see what will change. This can be done in chrome://flags

enter image description here

After these changes I see a message in the console, telling me that a cookie was blocked.

enter image description here

But the Application view in Chrome's developer tools shows exactly the same cookies as before.

Also, I went through each entry in the developer tools Network view. There is no Cookie tab for any of the entries.

This is very frustrating, as I do not know if thee blocked cookie is relevant for the functioning of our application.

Is there a way to find out which cookie was blocked? Can't Chrome just mention the cookie in the warning that it writes into the console?

Waruyama
  • 3,267
  • 1
  • 32
  • 42

1 Answers1

7

We've put together a more in-depth debugging guide here: https://www.chromium.org/updates/same-site/test-debug

As a tl;dr

  1. In the Network panel, select a request, go to the Cookies sub-tab, check the "show filtered out request cookies", and you can see each cookie along with the ones that were not included
  2. Capture a NetLog dump from Chrome and you can examine this in detail for the specific blocking events.
rowan_m
  • 2,893
  • 15
  • 18
  • Thanks, this helped a lot. I had read the guide before, but did not see the Cookies tab. Now that I tested again with the live version of our app I found everything. I probably tried the app on localhost before, where the Cookies tab did not show. – Waruyama Feb 06 '20 at 09:55
  • 1
    It turned out that the same cookie is set twice, probably to ensure compatibility with older browsers. This means we should be ready for the new SameSite policy. – Waruyama Feb 06 '20 at 10:09