Moodle 3.10.4+ iframe experience blocked in chrome version 92

Moodle 3.10.4+ iframe experience blocked in chrome version 92

by Shanushika Iswera -
Number of replies: 1

Hello Moodle,

We see that we have a potential issue with Chrome 92 (the latest version of Chrome) from launching our LTI 1.3 tool and our Deep Link UI application malfunctioning on Moodle 3.10 in an inframe experience. Moodle is presenting a sign-in screen that blocks from moving forward. 

Based on our investigation, We noticed that Chrome is blocking our request due to "SameSite" attribute not being set on the browser. 

  • Google Chrome version - 92.0.4515.131
  • Moodle - 3.10.4+ (Build: 20210611)

Note: This issue was not observed on Moodle version 3.10.4+ (Build: 20210604) on the same browser version. and we did not see this issue taking place on Firefox as well.

Do you know if this is something that is fixed in the newer moodle version? or if there is a workaround for this?


Moodle login screen 

Chrome - Response Headers

Average of ratings: -
In reply to Shanushika Iswera

Re: Moodle 3.10.4+ iframe experience blocked in chrome version 92

by Jake Dallimore -
Immàgine de Core developers Immàgine de Moodle HQ Immàgine de Particularly helpful Moodlers Immàgine de Peer reviewers Immàgine de Plugin developers Immàgine de Testers
Hi Shanushika,

We recently patched this problem with embedded launches. The issue was characterised by a set-cookie response header like you're seeing. See MDL-71887 for more information. You'll need to update your Moodle site to get access to this though, as it's not available in 3.10.4 - you need 3.10.6.

Cheers,
Jake