Thanks to visit codestin.com
Credit goes to Github.com

Skip to content
Discussion options

You must be logged in to vote

Hello,
yes, there are still use cases for it. They have different attributes.

  1. Non-legacy cookies have SameSite=None set; legacy cookies don't have SameSite set at all.
  2. Non-legacy cookies always have Secure flag, i.e. can be accessed only via SSL (this is mandatory for SameSite=None); legacy cookies respect the Realm setting for the Secure attribute (that is by default only for external requests is SSL required to access the cookies)

Non-legacy cookies are used in 3rd party contexts, when KC cookies need to be accessed from another hostname, typically by the JS adapter.

Legacy cookies are required as a workaround for older Apple devices that had a bug [1] in SameSite handling. Also, than…

Replies: 1 comment 6 replies

Comment options

You must be logged in to vote
6 replies
@vmuzikar
Comment options

vmuzikar Dec 2, 2021
Collaborator

@stianst
Comment options

@vmuzikar
Comment options

vmuzikar Dec 2, 2021
Collaborator

@stianst
Comment options

@vmuzikar
Comment options

vmuzikar Dec 2, 2021
Collaborator

Answer selected by vmuzikar
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants