NEW SameSite=None; Secure Cookie Settings breaks LTI

NEW SameSite=None; Secure Cookie Settings breaks LTI

by Veronica Volz -
Number of replies: 3

With Chrome 80 in February, Chrome will treat cookies that have no declared SameSite value as SameSite=Lax cookies. Only cookies with the SameSite=None; Secure setting will be available for external access, provided they are being accessed from secure connections. The Chrome Platform Status trackers for SameSite=None and Secure will continue to be updated with the latest launch information.

Mozilla has affirmed their support of the new cookie classification model with their intent to implement the SameSite=None; Secure requirements for cross-site cookies in Firefox. Microsoft recently announced plans to begin implementing the model starting as an experiment in Microsoft Edge 80.

I believe that the Publish to LTI tool in Moodle will be affected by this!

I have enabled the Experimental Features for  #same-site-by-default-cookies and #cookies-without-same-site-must-be-secure in chrome://flags/ and the LTI links I have published to Schoology are broken and revert back to the Login screen. 

Does anyone know if this will be fixed in an upcoming Moodle release?

Average of ratings: -
In reply to Veronica Volz

Re: NEW SameSite=None; Secure Cookie Settings breaks LTI

by Ramon Figueroa -
I have the exact same problem. sad
In reply to Ramon Figueroa

Re: NEW SameSite=None; Secure Cookie Settings breaks LTI

by Veronica Volz -

This has been fixed. You will need to update to Moodle 3.8.1+.

In reply to Veronica Volz

Re: NEW SameSite=None; Secure Cookie Settings breaks LTI

by Randy Thornton -
Picture of Documentation writers
This fix has also been backported to 3.5.11, 3.6.9, 3.7.5 as well, per MDL-67175.
Average of ratings: Useful (1)