5762fdd80041007bcb363f89c3a3589acc907295ac73cf7cb08ddd3ba539502f26a7e98518a6c87b740861c091f80f849d5196798b728b88ca226530845070 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733
  1. {
  2. "title":"'SameSite' cookie attribute",
  3. "description":"Same-site cookies (\"First-Party-Only\" or \"First-Party\") allow servers to mitigate the risk of CSRF and information leakage attacks by asserting that a particular cookie should only be sent with requests initiated from the same registrable domain.",
  4. "spec":"https://tools.ietf.org/html/draft-ietf-httpbis-rfc6265bis-07",
  5. "status":"other",
  6. "links":[
  7. {
  8. "url":"https://www.sjoerdlangkemper.nl/2016/04/14/preventing-csrf-with-samesite-cookie-attribute/",
  9. "title":"Preventing CSRF with the same-site cookie attribute"
  10. },
  11. {
  12. "url":"https://bugzilla.mozilla.org/show_bug.cgi?id=795346",
  13. "title":"Mozilla Bug #795346: Add SameSite support for cookies"
  14. },
  15. {
  16. "url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1286861",
  17. "title":"Mozilla Bug #1286861, includes the patches that landed SameSite support in Firefox"
  18. },
  19. {
  20. "url":"https://developer.microsoft.com/en-us/microsoft-edge/status/samesitecookies/",
  21. "title":"Microsoft Edge Browser Status"
  22. },
  23. {
  24. "url":"https://blogs.windows.com/msedgedev/2018/05/17/samesite-cookies-microsoft-edge-internet-explorer/",
  25. "title":"MS Edge dev blog: \"Previewing support for same-site cookies in Microsoft Edge\""
  26. },
  27. {
  28. "url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1551798",
  29. "title":"Mozilla Bug #1551798: Prototype SameSite=Lax by default"
  30. },
  31. {
  32. "url":"https://peaceful-wing.glitch.me",
  33. "title":"Same-site cookies demonstration by Rowan Merewood"
  34. }
  35. ],
  36. "bugs":[
  37. {
  38. "description":"On [Safari in macOS before 10.14.4 and iOS before 12.2](https://bugs.webkit.org/show_bug.cgi?id=188165#c43), some authentication flows with a cross-site identity provider might fail when `SameSite=Lax` is used. See [the explanation and a workaround.](https://brockallen.com/2019/01/11/same-site-cookies-asp-net-core-and-external-authentication-providers/)"
  39. },
  40. {
  41. "description":"On [Safari before 12.1.1 and iOS before 12.3](https://trac.webkit.org/changeset/241918/webkit), manually visiting a redirection link to a cross-site omits `Lax` cookies from the cross-site request. See [the bug.](https://bugs.webkit.org/show_bug.cgi?id=196375)"
  42. }
  43. ],
  44. "categories":[
  45. "Security"
  46. ],
  47. "stats":{
  48. "ie":{
  49. "5.5":"n",
  50. "6":"n",
  51. "7":"n",
  52. "8":"n",
  53. "9":"n",
  54. "10":"n",
  55. "11":"a #1 #2"
  56. },
  57. "edge":{
  58. "12":"n",
  59. "13":"n",
  60. "14":"n",
  61. "15":"n",
  62. "16":"y #1",
  63. "17":"y #1",
  64. "18":"y",
  65. "79":"y",
  66. "80":"y",
  67. "81":"y",
  68. "83":"y",
  69. "84":"y",
  70. "85":"y",
  71. "86":"y #3",
  72. "87":"y #3",
  73. "88":"y #3",
  74. "89":"y #3",
  75. "90":"y #3",
  76. "91":"y #3",
  77. "92":"y #3",
  78. "93":"y #3",
  79. "94":"y #3",
  80. "95":"y #3",
  81. "96":"y #3",
  82. "97":"y #3",
  83. "98":"y #3",
  84. "99":"y #3",
  85. "100":"y #3",
  86. "101":"y #3",
  87. "102":"y #3",
  88. "103":"y #3",
  89. "104":"y #3",
  90. "105":"y #3",
  91. "106":"y #3",
  92. "107":"y #3",
  93. "108":"y #3",
  94. "109":"y #3",
  95. "110":"y #3",
  96. "111":"y #3",
  97. "112":"y #3",
  98. "113":"y #3",
  99. "114":"y #3",
  100. "115":"y #3",
  101. "116":"y #3",
  102. "117":"y #3",
  103. "118":"y #3",
  104. "119":"y #3",
  105. "120":"y #3",
  106. "121":"y #3",
  107. "122":"y #3",
  108. "123":"y #3",
  109. "124":"y #3",
  110. "125":"y #3",
  111. "126":"y #3",
  112. "127":"y #3",
  113. "128":"y #3",
  114. "129":"y #3",
  115. "130":"y #3",
  116. "131":"y #3",
  117. "132":"y #3",
  118. "133":"y #3",
  119. "134":"y #3",
  120. "135":"y #3",
  121. "136":"y #3",
  122. "137":"y #3",
  123. "138":"y #3",
  124. "139":"y #3",
  125. "140":"y #3"
  126. },
  127. "firefox":{
  128. "2":"n",
  129. "3":"n",
  130. "3.5":"n",
  131. "3.6":"n",
  132. "4":"n",
  133. "5":"n",
  134. "6":"n",
  135. "7":"n",
  136. "8":"n",
  137. "9":"n",
  138. "10":"n",
  139. "11":"n",
  140. "12":"n",
  141. "13":"n",
  142. "14":"n",
  143. "15":"n",
  144. "16":"n",
  145. "17":"n",
  146. "18":"n",
  147. "19":"n",
  148. "20":"n",
  149. "21":"n",
  150. "22":"n",
  151. "23":"n",
  152. "24":"n",
  153. "25":"n",
  154. "26":"n",
  155. "27":"n",
  156. "28":"n",
  157. "29":"n",
  158. "30":"n",
  159. "31":"n",
  160. "32":"n",
  161. "33":"n",
  162. "34":"n",
  163. "35":"n",
  164. "36":"n",
  165. "37":"n",
  166. "38":"n",
  167. "39":"n",
  168. "40":"n",
  169. "41":"n",
  170. "42":"n",
  171. "43":"n",
  172. "44":"n",
  173. "45":"n",
  174. "46":"n",
  175. "47":"n",
  176. "48":"n",
  177. "49":"n",
  178. "50":"n",
  179. "51":"n",
  180. "52":"n",
  181. "53":"n",
  182. "54":"n",
  183. "55":"n",
  184. "56":"n",
  185. "57":"n",
  186. "58":"n",
  187. "59":"n",
  188. "60":"y",
  189. "61":"y",
  190. "62":"y",
  191. "63":"y",
  192. "64":"y",
  193. "65":"y",
  194. "66":"y",
  195. "67":"y",
  196. "68":"y",
  197. "69":"y",
  198. "70":"y",
  199. "71":"y",
  200. "72":"y",
  201. "73":"y",
  202. "74":"y",
  203. "75":"y",
  204. "76":"y",
  205. "77":"y",
  206. "78":"y",
  207. "79":"y",
  208. "80":"y",
  209. "81":"y",
  210. "82":"y",
  211. "83":"y",
  212. "84":"y",
  213. "85":"y",
  214. "86":"y",
  215. "87":"y",
  216. "88":"y",
  217. "89":"y",
  218. "90":"y",
  219. "91":"y",
  220. "92":"y",
  221. "93":"y",
  222. "94":"y",
  223. "95":"y",
  224. "96":"y",
  225. "97":"y",
  226. "98":"y",
  227. "99":"y",
  228. "100":"y",
  229. "101":"y",
  230. "102":"y",
  231. "103":"y",
  232. "104":"y",
  233. "105":"y",
  234. "106":"y",
  235. "107":"y",
  236. "108":"y",
  237. "109":"y",
  238. "110":"y",
  239. "111":"y",
  240. "112":"y",
  241. "113":"y",
  242. "114":"y",
  243. "115":"y",
  244. "116":"y",
  245. "117":"y",
  246. "118":"y",
  247. "119":"y",
  248. "120":"y",
  249. "121":"y",
  250. "122":"y",
  251. "123":"y",
  252. "124":"y",
  253. "125":"y",
  254. "126":"y",
  255. "127":"y",
  256. "128":"y",
  257. "129":"y",
  258. "130":"y",
  259. "131":"y",
  260. "132":"y",
  261. "133":"y",
  262. "134":"y",
  263. "135":"y",
  264. "136":"y",
  265. "137":"y",
  266. "138":"y",
  267. "139":"y",
  268. "140":"y",
  269. "141":"y",
  270. "142":"y",
  271. "143":"y",
  272. "144":"y",
  273. "145":"y"
  274. },
  275. "chrome":{
  276. "4":"n",
  277. "5":"n",
  278. "6":"n",
  279. "7":"n",
  280. "8":"n",
  281. "9":"n",
  282. "10":"n",
  283. "11":"n",
  284. "12":"n",
  285. "13":"n",
  286. "14":"n",
  287. "15":"n",
  288. "16":"n",
  289. "17":"n",
  290. "18":"n",
  291. "19":"n",
  292. "20":"n",
  293. "21":"n",
  294. "22":"n",
  295. "23":"n",
  296. "24":"n",
  297. "25":"n",
  298. "26":"n",
  299. "27":"n",
  300. "28":"n",
  301. "29":"n",
  302. "30":"n",
  303. "31":"n",
  304. "32":"n",
  305. "33":"n",
  306. "34":"n",
  307. "35":"n",
  308. "36":"n",
  309. "37":"n",
  310. "38":"n",
  311. "39":"n",
  312. "40":"n",
  313. "41":"n",
  314. "42":"n",
  315. "43":"n",
  316. "44":"n",
  317. "45":"n",
  318. "46":"n",
  319. "47":"n",
  320. "48":"n",
  321. "49":"n",
  322. "50":"n",
  323. "51":"y",
  324. "52":"y",
  325. "53":"y",
  326. "54":"y",
  327. "55":"y",
  328. "56":"y",
  329. "57":"y",
  330. "58":"y",
  331. "59":"y",
  332. "60":"y",
  333. "61":"y",
  334. "62":"y",
  335. "63":"y",
  336. "64":"y",
  337. "65":"y",
  338. "66":"y",
  339. "67":"y",
  340. "68":"y",
  341. "69":"y",
  342. "70":"y",
  343. "71":"y",
  344. "72":"y",
  345. "73":"y",
  346. "74":"y",
  347. "75":"y",
  348. "76":"y",
  349. "77":"y",
  350. "78":"y",
  351. "79":"y",
  352. "80":"y #3",
  353. "81":"y #3",
  354. "83":"y #3",
  355. "84":"y #3",
  356. "85":"y #3",
  357. "86":"y #3",
  358. "87":"y #3",
  359. "88":"y #3",
  360. "89":"y #3",
  361. "90":"y #3",
  362. "91":"y #3",
  363. "92":"y #3",
  364. "93":"y #3",
  365. "94":"y #3",
  366. "95":"y #3",
  367. "96":"y #3",
  368. "97":"y #3",
  369. "98":"y #3",
  370. "99":"y #3",
  371. "100":"y #3",
  372. "101":"y #3",
  373. "102":"y #3",
  374. "103":"y #3",
  375. "104":"y #3",
  376. "105":"y #3",
  377. "106":"y #3",
  378. "107":"y #3",
  379. "108":"y #3",
  380. "109":"y #3",
  381. "110":"y #3",
  382. "111":"y #3",
  383. "112":"y #3",
  384. "113":"y #3",
  385. "114":"y #3",
  386. "115":"y #3",
  387. "116":"y #3",
  388. "117":"y #3",
  389. "118":"y #3",
  390. "119":"y #3",
  391. "120":"y #3",
  392. "121":"y #3",
  393. "122":"y #3",
  394. "123":"y #3",
  395. "124":"y #3",
  396. "125":"y #3",
  397. "126":"y #3",
  398. "127":"y #3",
  399. "128":"y #3",
  400. "129":"y #3",
  401. "130":"y #3",
  402. "131":"y #3",
  403. "132":"y #3",
  404. "133":"y #3",
  405. "134":"y #3",
  406. "135":"y #3",
  407. "136":"y #3",
  408. "137":"y #3",
  409. "138":"y #3",
  410. "139":"y #3",
  411. "140":"y #3",
  412. "141":"y #3",
  413. "142":"y #3",
  414. "143":"y #3"
  415. },
  416. "safari":{
  417. "3.1":"n",
  418. "3.2":"n",
  419. "4":"n",
  420. "5":"n",
  421. "5.1":"n",
  422. "6":"n",
  423. "6.1":"n",
  424. "7":"n",
  425. "7.1":"n",
  426. "8":"n",
  427. "9":"n",
  428. "9.1":"n",
  429. "10":"n",
  430. "10.1":"n",
  431. "11":"n",
  432. "11.1":"n",
  433. "12":"a #4 #5",
  434. "12.1":"a #4 #5",
  435. "13":"a #4 #5",
  436. "13.1":"a #4 #5",
  437. "14":"a #5",
  438. "14.1":"a #5",
  439. "15":"y",
  440. "15.1":"y",
  441. "15.2-15.3":"y",
  442. "15.4":"y",
  443. "15.5":"y",
  444. "15.6":"y",
  445. "16.0":"y",
  446. "16.1":"y",
  447. "16.2":"y",
  448. "16.3":"y",
  449. "16.4":"y",
  450. "16.5":"y",
  451. "16.6":"y",
  452. "17.0":"y",
  453. "17.1":"y",
  454. "17.2":"y",
  455. "17.3":"y",
  456. "17.4":"y",
  457. "17.5":"y",
  458. "17.6":"y",
  459. "18.0":"y",
  460. "18.1":"y",
  461. "18.2":"y",
  462. "18.3":"y",
  463. "18.4":"y",
  464. "18.5-18.6":"y",
  465. "26.0":"y",
  466. "26.1":"y",
  467. "TP":"y"
  468. },
  469. "opera":{
  470. "9":"n",
  471. "9.5-9.6":"n",
  472. "10.0-10.1":"n",
  473. "10.5":"n",
  474. "10.6":"n",
  475. "11":"n",
  476. "11.1":"n",
  477. "11.5":"n",
  478. "11.6":"n",
  479. "12":"n",
  480. "12.1":"n",
  481. "15":"n",
  482. "16":"n",
  483. "17":"n",
  484. "18":"n",
  485. "19":"n",
  486. "20":"n",
  487. "21":"n",
  488. "22":"n",
  489. "23":"n",
  490. "24":"n",
  491. "25":"n",
  492. "26":"n",
  493. "27":"n",
  494. "28":"n",
  495. "29":"n",
  496. "30":"n",
  497. "31":"n",
  498. "32":"n",
  499. "33":"n",
  500. "34":"n",
  501. "35":"n",
  502. "36":"n",
  503. "37":"n",
  504. "38":"n",
  505. "39":"y",
  506. "40":"y",
  507. "41":"y",
  508. "42":"y",
  509. "43":"y",
  510. "44":"y",
  511. "45":"y",
  512. "46":"y",
  513. "47":"y",
  514. "48":"y",
  515. "49":"y",
  516. "50":"y",
  517. "51":"y",
  518. "52":"y",
  519. "53":"y",
  520. "54":"y",
  521. "55":"y",
  522. "56":"y",
  523. "57":"y",
  524. "58":"y",
  525. "60":"y",
  526. "62":"y",
  527. "63":"y",
  528. "64":"y",
  529. "65":"y",
  530. "66":"y",
  531. "67":"y",
  532. "68":"y",
  533. "69":"y",
  534. "70":"y",
  535. "71":"y #3",
  536. "72":"y #3",
  537. "73":"y #3",
  538. "74":"y #3",
  539. "75":"y #3",
  540. "76":"y #3",
  541. "77":"y #3",
  542. "78":"y #3",
  543. "79":"y #3",
  544. "80":"y #3",
  545. "81":"y #3",
  546. "82":"y #3",
  547. "83":"y #3",
  548. "84":"y #3",
  549. "85":"y #3",
  550. "86":"y #3",
  551. "87":"y #3",
  552. "88":"y #3",
  553. "89":"y #3",
  554. "90":"y #3",
  555. "91":"y #3",
  556. "92":"y #3",
  557. "93":"y #3",
  558. "94":"y #3",
  559. "95":"y #3",
  560. "96":"y #3",
  561. "97":"y #3",
  562. "98":"y #3",
  563. "99":"y #3",
  564. "100":"y #3",
  565. "101":"y #3",
  566. "102":"y #3",
  567. "103":"y #3",
  568. "104":"y #3",
  569. "105":"y #3",
  570. "106":"y #3",
  571. "107":"y #3",
  572. "108":"y #3",
  573. "109":"y #3",
  574. "110":"y #3",
  575. "111":"y #3",
  576. "112":"y #3",
  577. "113":"y #3",
  578. "114":"y #3",
  579. "115":"y #3",
  580. "116":"y #3",
  581. "117":"y #3",
  582. "118":"y #3",
  583. "119":"y #3",
  584. "120":"y #3",
  585. "121":"y #3",
  586. "122":"y #3"
  587. },
  588. "ios_saf":{
  589. "3.2":"n",
  590. "4.0-4.1":"n",
  591. "4.2-4.3":"n",
  592. "5.0-5.1":"n",
  593. "6.0-6.1":"n",
  594. "7.0-7.1":"n",
  595. "8":"n",
  596. "8.1-8.4":"n",
  597. "9.0-9.2":"n",
  598. "9.3":"n",
  599. "10.0-10.2":"n",
  600. "10.3":"n",
  601. "11.0-11.2":"n",
  602. "11.3-11.4":"n",
  603. "12.0-12.1":"a #5",
  604. "12.2-12.5":"a #5",
  605. "13.0-13.1":"y",
  606. "13.2":"y",
  607. "13.3":"y",
  608. "13.4-13.7":"y",
  609. "14.0-14.4":"y",
  610. "14.5-14.8":"y",
  611. "15.0-15.1":"y",
  612. "15.2-15.3":"y",
  613. "15.4":"y",
  614. "15.5":"y",
  615. "15.6-15.8":"y",
  616. "16.0":"y",
  617. "16.1":"y",
  618. "16.2":"y",
  619. "16.3":"y",
  620. "16.4":"y",
  621. "16.5":"y",
  622. "16.6-16.7":"y",
  623. "17.0":"y",
  624. "17.1":"y",
  625. "17.2":"y",
  626. "17.3":"y",
  627. "17.4":"y",
  628. "17.5":"y",
  629. "17.6-17.7":"y",
  630. "18.0":"y",
  631. "18.1":"y",
  632. "18.2":"y",
  633. "18.3":"y",
  634. "18.4":"y",
  635. "18.5-18.6":"y",
  636. "26.0":"y",
  637. "26.1":"y"
  638. },
  639. "op_mini":{
  640. "all":"n"
  641. },
  642. "android":{
  643. "2.1":"n",
  644. "2.2":"n",
  645. "2.3":"n",
  646. "3":"n",
  647. "4":"n",
  648. "4.1":"n",
  649. "4.2-4.3":"n",
  650. "4.4":"n",
  651. "4.4.3-4.4.4":"n",
  652. "139":"y"
  653. },
  654. "bb":{
  655. "7":"n",
  656. "10":"n"
  657. },
  658. "op_mob":{
  659. "10":"n",
  660. "11":"n",
  661. "11.1":"n",
  662. "11.5":"n",
  663. "12":"n",
  664. "12.1":"n",
  665. "80":"y #3"
  666. },
  667. "and_chr":{
  668. "139":"y #3"
  669. },
  670. "and_ff":{
  671. "142":"y"
  672. },
  673. "ie_mob":{
  674. "10":"n",
  675. "11":"n"
  676. },
  677. "and_uc":{
  678. "15.5":"n"
  679. },
  680. "samsung":{
  681. "4":"n",
  682. "5.0-5.4":"y",
  683. "6.2-6.4":"y",
  684. "7.2-7.4":"y",
  685. "8.2":"y",
  686. "9.2":"y",
  687. "10.1":"y",
  688. "11.1-11.2":"y",
  689. "12.0":"y",
  690. "13.0":"y",
  691. "14.0":"y",
  692. "15.0":"y",
  693. "16.0":"y",
  694. "17.0":"y",
  695. "18.0":"y",
  696. "19.0":"y",
  697. "20":"y",
  698. "21":"y",
  699. "22":"y",
  700. "23":"y",
  701. "24":"y",
  702. "25":"y",
  703. "26":"y",
  704. "27":"y",
  705. "28":"y"
  706. },
  707. "and_qq":{
  708. "14.9":"u"
  709. },
  710. "baidu":{
  711. "13.52":"y #3"
  712. },
  713. "kaios":{
  714. "2.5":"n",
  715. "3.0-3.1":"y"
  716. }
  717. },
  718. "notes":"This feature is backwards compatible. Browsers not supporting this feature will simply use the cookie as a regular cookie. There is no need to deliver different cookies to clients.",
  719. "notes_by_num":{
  720. "1":"Not shipped with the initial release but later with the 2018 June security update (Patch Tuesday) to Windows 10 RS3 (2017 Fall Creators Update) and newer. [More info](https://github.com/MicrosoftEdge/Status/issues/616).",
  721. "2":"Partial support because only supported in IE 11 on Windows 10 RS3 (2017 Fall Creators Update) and newer, but not in IE 11 on other Windows versions (Windows 7, ...)",
  722. "3":"Cookies without `SameSite` are treated as `Lax` by default, `SameSite=None` cookies without `Secure` are rejected.",
  723. "4":"Partial due to the lack of support in macOS before 10.14 Mojave.",
  724. "5":"Partial due to [the bug](https://bugs.webkit.org/show_bug.cgi?id=198181) that treats `SameSite=None` and invalid values as `Strict` in macOS before 10.15 Catalina and in iOS before 13."
  725. },
  726. "usage_perc_y":94.1,
  727. "usage_perc_a":0.82,
  728. "ucprefix":false,
  729. "parent":"",
  730. "keywords":"security,cookies,cookie,csrf",
  731. "chrome_id":"4672634709082112,5088147346030592,5633521622188032",
  732. "shown":true
  733. }