Join us to show up for other Firefox users 🦊. Earn fun badges and Mozilla swag vouchers! Find out more: https://mzl.la/askafox150

Windows 10 reached EOS (end of support) on October 14, 2025. If you are on Windows 10, see this article.

Vyhľadajte odpoveď

Vyhnite sa podvodom s podporou. Nikdy vás nebudeme žiadať, aby ste zavolali alebo poslali SMS na telefónne číslo alebo zdieľali osobné informácie. Nahláste prosím podozrivú aktivitu použitím voľby “Nahlásiť zneužitie”.

Ďalšie informácie

SameSite flag no longer default?

  • 7 odpovedí
  • 0 má tento problém
  • 67 zobrazení
  • Posledná odpoveď od Denys
  • Vyriešené

Hi,

I noticed that in the latest release (I tried both MacOS and Windows 11 ARM versions) that the "network.cookie.sameSite.laxByDefault" is no longer enabled, and cookies set by applications without specifying the flag, are not set with Lax and are sent in cross-origin requests. Could you clarify if this is intentional and why the change has been made?

Thanks

Hi, I noticed that in the latest release (I tried both MacOS and Windows 11 ARM versions) that the "network.cookie.sameSite.laxByDefault" is no longer enabled, and cookies set by applications without specifying the flag, are not set with Lax and are sent in cross-origin requests. Could you clarify if this is intentional and why the change has been made? Thanks
Priložené obrázky

Vybrané riešenie

It was disabled much longer for me. They didn't plan to ship laxByDefault since 2024.

I don't think that something has been changed about it in 149.

Čítať túto odpoveď v kontexte 👍 1

Všetky odpovede (7)

Version 149.0 by the way

Vybrané riešenie

It was disabled much longer for me. They didn't plan to ship laxByDefault since 2024.

I don't think that something has been changed about it in 149.

Any reference on the rollback from defaulting to Lax? I can easily find that it was defaulted to Lax around 2020 or 2021, but can't find any reference or announcement around not being the default any longer. Most of the peers I deal with assumed and thought Firefox still defaulted, so FYI

See also:

(please do not comment in bug reports
https://bugzilla.mozilla.org/page.cgi?id=etiquette.html
)

Bit different from this type of announcement https://hacks.mozilla.org/2020/08/changes-to-samesite-cookie-behavior/

Anyway.... Thanks for the clarification

Hi,

Since the answer appears to be found, I've marked TyDraniu's reply above as a solution to highlight it for other users. If you disagree, you can click the Undo button under it and then mark any other reply as a solution,

Položiť otázku

Ak chcete odpovedať na príspevky, musíte sa prihlásiť do svojho účtu. Ak ešte nemáte účet, položte novú otázku.