hypothesis / hypothesis/h

Cookie SameSite defaulting to Lax instead of None in more and more browser - Cookie h_api_authcookie.v2 rejected in iFrame

Open
#9,243 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
3.2k
Forks
459
Avg merge
27d 1h
Merged PRs (30d)
1

Description

Hi

I am happy using pdf.js + hypothes.is in an iframe on the website of a learned society that produced many documents in pdf format.

I have noticed in the browser console that Cookie h_api_authcookie.v2 is rejected, most probably because SameSite now defaults to Lax instead of None.
That does not seem to block the use of hypothes.is in an iframe but implementing "Secure;SameSite=None" may help and recommendations would be very nice

Many thanks

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.