NEW SameSite=None; Secure Cookie Settings breaks LTI

NEW SameSite=None; Secure Cookie Settings breaks LTI

de Veronica Volz -
Número de respuestas: 3

With Chrome 80 in February, Chrome will treat cookies that have no declared SameSite value as SameSite=Lax cookies. Only cookies with the SameSite=None; Secure setting will be available for external access, provided they are being accessed from secure connections. The Chrome Platform Status trackers for SameSite=None and Secure will continue to be updated with the latest launch information.

Mozilla has affirmed their support of the new cookie classification model with their intent to implement the SameSite=None; Secure requirements for cross-site cookies in Firefox. Microsoft recently announced plans to begin implementing the model starting as an experiment in Microsoft Edge 80.

I believe that the Publish to LTI tool in Moodle will be affected by this!

I have enabled the Experimental Features for  #same-site-by-default-cookies and #cookies-without-same-site-must-be-secure in chrome://flags/ and the LTI links I have published to Schoology are broken and revert back to the Login screen. 

Does anyone know if this will be fixed in an upcoming Moodle release?

Promedio de valoraciones: -
En respuesta a Veronica Volz

Re: NEW SameSite=None; Secure Cookie Settings breaks LTI

de Ramon Figueroa -
I have the exact same problem. triste
En respuesta a Ramon Figueroa

Re: NEW SameSite=None; Secure Cookie Settings breaks LTI

de Veronica Volz -

This has been fixed. You will need to update to Moodle 3.8.1+.