SameSite Cookie Attribute Explained by Example (Strict, Lax, None & No SameSite)

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 ก.ย. 2024

ความคิดเห็น • 122

  • @hnasr
    @hnasr  7 หลายเดือนก่อน +5

    google has started deprecating Third party cookies (samesite=none essentially) in 2024. You might be among the 1% experiment. that might explain why it's working anymore. I wrote about this here and left resources too.
    medium.com/@hnasr/google-is-deprecating-3rd-party-cookies-d987603607a7

    • @ammakr
      @ammakr 6 หลายเดือนก่อน

      Yeah, I just noticed. I have a web application in nextjs and django. It's working fine on Firefox and GNOME Web (a.k.a. Safari lol), but it's authentication stopped working on Chromium (cookies aren't being set). Thanks man!

  • @williambattle5068
    @williambattle5068 2 ปีที่แล้ว +8

    Thanks a bunch - just what I needed! I found the explanation in a lot of places but the visuals really clarified it for me.

  • @vicky2118
    @vicky2118 3 ปีที่แล้ว +8

    Finally I understood this concept... Thanks for this great explanation 👍

    • @hnasr
      @hnasr  3 ปีที่แล้ว

      ❤️

  • @gagangupta1255
    @gagangupta1255 4 ปีที่แล้ว +4

    Hussein go bless for explaining this feature so nicely. Even after reading/watching 10's of video - the concept was not clear. Seriously you did a great job explaining it so easily with a practical example

    • @hnasr
      @hnasr  4 ปีที่แล้ว +1

      Gagan Gupta Hi Gogan! I am happy the video helped 😊 have a great day

  • @_dinesh
    @_dinesh 4 ปีที่แล้ว +10

    This is how you explain things!!!!! Thank you so much 🙏🙏🙏. Google Chrome team should use this as their office video because their video is just a crap.

  • @iamboltzmann412
    @iamboltzmann412 3 หลายเดือนก่อน +1

    Thanks a lot brother, I recently made a new website and the front end and backend are hosted on two different services, I was breaking my head over why the browser was not sending cookies. This explains why. I guess I have to use some other way, since google deprecated cross site cookies

  • @ashish_gupta307
    @ashish_gupta307 2 ปีที่แล้ว

    I checked for this topic on many channels but got it clear from here.....thanks hussein.

  • @justcoding2491
    @justcoding2491 2 ปีที่แล้ว +3

    Very well explained in detail with good example ❤️👍🏻

  • @namangupta1817
    @namangupta1817 3 ปีที่แล้ว +3

    That excitement level for domain name 😂😂😂😂😂

  • @JiyOnFire-vg4xx
    @JiyOnFire-vg4xx 11 หลายเดือนก่อน

    Thank u sooo much sir. I was searching for it the whole day but I didn't understand before u explained it. It's really precious

  • @AUBCodeII
    @AUBCodeII ปีที่แล้ว +1

    Thanks for making a clear explanation of SameSite!

  • @samnayakawadi
    @samnayakawadi 11 หลายเดือนก่อน

    Subscribed. ChatGPT failed to explain this concept. Thanks dude.

  • @Ravi.Benedetti
    @Ravi.Benedetti 4 ปีที่แล้ว +2

    Thank you sir. You are a gentleman and a scholar.

  • @shadmanfatin777
    @shadmanfatin777 ปีที่แล้ว +1

    Amazing explanation. Thank you Nasser sir.

  • @g-luu
    @g-luu 4 ปีที่แล้ว +5

    Superior content as always.

    • @hnasr
      @hnasr  4 ปีที่แล้ว

      Thanks Bryan !

  • @MrMonishSoni
    @MrMonishSoni ปีที่แล้ว

    Best video for samesite Attribute (Cookies)

  • @thoriq_aulia
    @thoriq_aulia 2 ปีที่แล้ว

    Finally I understand about sameSite parameter, Thx man you save the day

  • @rohandvivedi
    @rohandvivedi 3 ปีที่แล้ว +1

    This is one of the best illustration for the usage of samesite.
    thanks

    • @hnasr
      @hnasr  3 ปีที่แล้ว

      Rohan Dvivedi thanks Rohan

  • @supa1009
    @supa1009 4 ปีที่แล้ว +4

    haha thanks for the tutorial and positive energy :D

  • @thalyssonleite1479
    @thalyssonleite1479 2 ปีที่แล้ว +1

    Thank you! It's very clear now what that cookie with sameSite do

    • @isbemorph
      @isbemorph ปีที่แล้ว

      Node would throw a typo. But samesite or SameSite works fine..

  • @rotemgalea7156
    @rotemgalea7156 ปีที่แล้ว

    thanks god! I learned this in collage that i paid a lot of money. and now it the first time i really understand this issu . thank you

  • @shuaiqingluo4400
    @shuaiqingluo4400 7 หลายเดือนก่อน

    this is an excellent video explaining the same-site policy of cookies!

  • @ebaduddin2624
    @ebaduddin2624 3 ปีที่แล้ว +1

    beautifully explained..thanks

  • @nitinverma7419
    @nitinverma7419 3 หลายเดือนก่อน

    Thanks brother, You saved a lot of time for me :)

  • @surajbhushanpandey2882
    @surajbhushanpandey2882 2 ปีที่แล้ว

    Nice work @ Hussein

  • @pedrosampaio8293
    @pedrosampaio8293 3 ปีที่แล้ว +1

    Brilliant explanation!!!

  • @thalyssonleite1479
    @thalyssonleite1479 2 ปีที่แล้ว

    Greetings from Brazil!

  • @alexeicodes
    @alexeicodes ปีที่แล้ว

    The best explanation i love it so much

  • @ashherali7613
    @ashherali7613 10 หลายเดือนก่อน

    nice explanation keep it up dude

  • @matthewespindola3694
    @matthewespindola3694 3 ปีที่แล้ว

    Wow, you are great man. What a perfect explanation. Thanks!

  • @roman_mf
    @roman_mf ปีที่แล้ว

    Beautifully visualized!

  • @kumaravelrajan
    @kumaravelrajan ปีที่แล้ว

    Excellent presentation. Thank you 😁

  • @user-qb1yq6ji2o
    @user-qb1yq6ji2o 9 หลายเดือนก่อน

    Thank you for the information. It was really useful.

  • @user-mu5il5in3g
    @user-mu5il5in3g 11 หลายเดือนก่อน

    Amazing explaination !! thanks a ton!!!

  • @channaly2772
    @channaly2772 ปีที่แล้ว

    Great example! Many thanks

  • @DevAmirull
    @DevAmirull ปีที่แล้ว

    What a perfect explanation. Thanks.

  • @QuranKareem22
    @QuranKareem22 8 หลายเดือนก่อน

    good explanation thanks!

  • @raminiskandarov
    @raminiskandarov 2 ปีที่แล้ว

    Thanks for this perfect explanation. just perfect

  • @yaseralamoodi8314
    @yaseralamoodi8314 4 ปีที่แล้ว +3

    Thank brother I really appreciate your work and get a lot of experience from you, my question is isn't cookies shloud just work for the same domain?، I mean it shouldn't be exists if you open a new tab for another domain

    • @hnasr
      @hnasr  4 ปีที่แล้ว +4

      Correct ! Cookie are domain specific, but 3rd party cookies were invented for tracking purposes

  • @MedoMedo-op3em
    @MedoMedo-op3em 3 ปีที่แล้ว +1

    BRILLIANT !!

  • @MrJohn360
    @MrJohn360 3 ปีที่แล้ว

    Great explanation, thanks for sharing.

  • @ismaillachhab741
    @ismaillachhab741 2 ปีที่แล้ว

    Good explanation , Thank you so much

  • @bum7006
    @bum7006 3 ปีที่แล้ว +1

    Thanks

  • @mrstatler
    @mrstatler 5 หลายเดือนก่อน

    Still don't know why there's cookie for the second site referencing image from the first one when both are open in chrome. But when one is open in chrome & 2nd in fox it doesn't seem to work.

  • @nileshmonde4707
    @nileshmonde4707 ปีที่แล้ว

    Thanks for the video

  • @nikhil_arora
    @nikhil_arora 2 ปีที่แล้ว

    too good. thanks for this video!

  • @techwithameer
    @techwithameer 4 ปีที่แล้ว +1

    Thanks for this bro...

  • @birdofhermes6152
    @birdofhermes6152 3 ปีที่แล้ว

    Thanks for the explanation

  • @tsdineshjai8565
    @tsdineshjai8565 หลายเดือนก่อน

    @hnasr usually when you visit a site, the server will send the cookie to the browser right. But in the video, you have mentioned several times that "Browser" will not send the cookie if it's cross site. Can you explain on this please ?

  • @dmbarry86
    @dmbarry86 4 ปีที่แล้ว

    Brilliant explanation, thanks.

    • @hnasr
      @hnasr  4 ปีที่แล้ว

      Glad it was helpful!

  • @aliyevruslan936
    @aliyevruslan936 ปีที่แล้ว

    @hnasr The server setup things you mentioned at ~ 1.56m, which of your video teaches such server setups? You have many videos

  • @saeedp92
    @saeedp92 5 หลายเดือนก่อน

    excellent thank you

  • @alvin_lal
    @alvin_lal 3 ปีที่แล้ว

    Thanks sir, very helpful

  • @bojandanon2037
    @bojandanon2037 ปีที่แล้ว

    Very nice 👍

  • @nishantdalvi9470
    @nishantdalvi9470 10 หลายเดือนก่อน

    Please some one clear my doubt, The image of one domain is getting loaded on another domain if the attribute Same-site has the value None right but what about the SOP (Same Origin Policy) ain't it gonna block the responses from cross domain ?

  • @jyotirmoymaschatak5960
    @jyotirmoymaschatak5960 ปีที่แล้ว

    Thanks Boss!

  • @ExtraTurtle
    @ExtraTurtle 9 หลายเดือนก่อน

    what makes the image display only with the cookie? I thought the cookie being strict means it lets you access the cookie itself from the same site only. where is the code for the img, and how do you make it follow the cookie settings?

  • @allanimeworld2898
    @allanimeworld2898 3 ปีที่แล้ว +1

    Sir please make a video on how to access cookie from other website.
    Means how cross-site is done.
    🙏🙏🙏🙏🙏🙏🙏🙏🙏🙏🙏🙏🙏

  • @manikandankm3974
    @manikandankm3974 2 ปีที่แล้ว

    What if we want to make any request from Domain A through api call to fetch information from Domain B when same site = Strict ? what is the way to achieve the same

  • @alimahboub4163
    @alimahboub4163 3 ปีที่แล้ว

    That's the best explanation ever! Well done my friend. Keep it going

  • @goatslayer5957
    @goatslayer5957 7 หลายเดือนก่อน

    Is it possible they have patched this? I can't get cross-site cookies working! I used your express file and uploaded to render. Then I also made a GitHub page with an image src pointing to the render https link, but the cookie is never sent!!

  • @ManiKandan-vo2qr
    @ManiKandan-vo2qr 4 ปีที่แล้ว

    Hi , I have a small doubt . What would be the case when it is not Secure . Please let me know the behavior when both are communicating with HTTP

  • @AbhiSeSeekho
    @AbhiSeSeekho 3 ปีที่แล้ว

    If same site attribute is set to lax the browser is sending the cookie then how it prevent csrf?

  • @mishapatel3119
    @mishapatel3119 3 ปีที่แล้ว

    How Can we access the cookies in request header with httpOnly ?? Plz help i m in trouble to get these cookies in all request header

  • @petruconiuc4618
    @petruconiuc4618 3 ปีที่แล้ว +1

    Very impressive explanation, but how do you set a cookie with a domain other than your own?

    • @hnasr
      @hnasr  3 ปีที่แล้ว

      You can’t that is the security aspect of cookies. They are set by the owner of the domain
      You can set the cookie from the client side with Javascript document.cookie but still you would have injected some code to do so in someone else’s domain

  • @ektanawle1088
    @ektanawle1088 4 ปีที่แล้ว

    Thanks for the explanation Hussein. I got one question ..if someone is using my site login page on their website then who would set the samesite : none
    (I as a site owner or the one who is using our login page). Could you please help me find this.
    I have set in my code samesite:none but when I am trying to login through their site it still showing samesite:Lax while when I login through mysite changes are reflecting as none

  • @morganfree100
    @morganfree100 2 ปีที่แล้ว

    @hussein Nasser: Does this applies to webscoket?

  • @desarrolladorrapido8767
    @desarrolladorrapido8767 4 ปีที่แล้ว

    Excellent example with IMG and A, a question, How about IFRAME and AJAX?

    • @hnasr
      @hnasr  4 ปีที่แล้ว +1

      Desarrollador Rápido both are very similar to IMG. Thanks!

    • @desarrolladorrapido8767
      @desarrolladorrapido8767 4 ปีที่แล้ว

      I see, thank you.

    • @glenndwiyatcita1663
      @glenndwiyatcita1663 3 ปีที่แล้ว

      @@hnasr Hmm but according to owasp.org/www-community/attacks/csrf#other-http-methods, JavaScript is subject to same-origin policy. ...which means if AJAX is used to make a request from your other origin (hnasr.github.io), it won't be executed in the first place.

  • @shubham_srt
    @shubham_srt ปีที่แล้ว

    Thanks :)

  • @nguyenluat-gj8vx
    @nguyenluat-gj8vx 5 หลายเดือนก่อน

    thanks

  • @singh.karanbir
    @singh.karanbir 3 ปีที่แล้ว

    This is nice explanation
    But there is a room for explanation around the cookies being set while calling login api

  • @smartaquarius2021
    @smartaquarius2021 3 ปีที่แล้ว

    Is it possible to access samesite lax cookie in case api is integrated with openid connect for single sign on. Currently why they are inaccessible because oidc url auto redirects to my api and at that time api try to read the cookies at server side. Any suggestions on this please??

  • @quangaonguyen7898
    @quangaonguyen7898 2 ปีที่แล้ว

    How do we set samesite = none?

  • @vladislavgerginov748
    @vladislavgerginov748 ปีที่แล้ว

    Thanks for the great example. But how do you set these properties on a site with a drag-and-drop site builder is the real question?

    • @urssaf343
      @urssaf343 ปีที่แล้ว

      This is done on the backend. Drag and drop stuff is just the page that is being sent to the user.

    • @vladislavgerginov748
      @vladislavgerginov748 ปีที่แล้ว

      @@urssaf343 agree to that. A tutorial about how it's done on the back end will be very appreciated. Or it's too much to ask?!

    • @urssaf343
      @urssaf343 ปีที่แล้ว +1

      @@vladislavgerginov748 Lookup course from Mosh Hamedani: restful apis with express.

  • @iCydiaHelper19
    @iCydiaHelper19 3 ปีที่แล้ว

    I am getting HTTP error 405, any advices?

  • @utkuaslan701
    @utkuaslan701 4 ปีที่แล้ว

    thanks!!

  • @techwithameer
    @techwithameer 4 ปีที่แล้ว

    why redirection to a site not working when same site is lax but the request from another site is 'post'?
    will this works only for 'GET'?
    Iam getting issue when my my site is redirected from a payment gateway. They are redirecting using a POST request.

    • @hnasr
      @hnasr  4 ปีที่แล้ว +1

      AMR K Post requests won’t send lax cookies to cross site, there is however an exception if those lax cookies are created within two minutes
      A SameSite Cookie Exception was made to avoid Redirect Loop in Single Sign-On (SSO) Let us Discuss
      th-cam.com/video/4QiD8cvzCN0/w-d-xo.html

  • @techwithameer
    @techwithameer 4 ปีที่แล้ว

    I need same site mode strict but then my redirection from a payment site is not working.
    Is there any solution to keep it working without changing same site strict mode?

    • @hnasr
      @hnasr  4 ปีที่แล้ว +1

      I think its safe to use lax for your use case since you are redirecting. I don’t know if you can use strict and still send the cookies while redirecting..

  • @gokusupersayiandbgt
    @gokusupersayiandbgt 4 ปีที่แล้ว

    Hi, does thed same site attribute provide protection on all browsers like IE, Firefox or just chrome latest

    • @hnasr
      @hnasr  4 ปีที่แล้ว

      nvn dnt Correct all browsers now supports it except for IE developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite

  • @MaheshBh6
    @MaheshBh6 2 ปีที่แล้ว

    Stating the obvious here but this is a HTTPS only feature, so the flags won't work in any dev environments that don't have https configured

  • @Jamie-pq9gn
    @Jamie-pq9gn 3 ปีที่แล้ว

    Hi Nasser, I have a question, How is https in the video implemented? No certificate is imported in the source code.

    • @hnasr
      @hnasr  3 ปีที่แล้ว

      Hey , I skipped that part since I explained it on other videos th-cam.com/video/b35Dcz91ItE/w-d-xo.html

    • @Jamie-pq9gn
      @Jamie-pq9gn 3 ปีที่แล้ว

      @@hnasr thank you very much 🙏

  • @alii4334
    @alii4334 2 ปีที่แล้ว

    you can keep the devtools open!

  • @mursalrabb6093
    @mursalrabb6093 3 ปีที่แล้ว

    same-site = None useless? i'd say no. Its pretty useful during development phase when your frontend and backend are running at different ports

  • @ca7986
    @ca7986 4 ปีที่แล้ว

    ❤️

  • @hnasr
    @hnasr  4 ปีที่แล้ว +4

    Still Having trouble with SameSite? Rowan from Google is willing to help one-on-one check his twitter twitter.com/rowan_m/status/1280821505757044736?s=21

    • @RowanMerewood
      @RowanMerewood 4 ปีที่แล้ว

      Thanks, Hussein! Definitely happy to chat with people. Hearing about the issues people are having helps me in turn improve the documentation and samples too.

    • @FLUTTERMAD
      @FLUTTERMAD 4 ปีที่แล้ว

      What if cookies are available for specified domain or path, but SameSite is Lax/None?

    • @RowanMerewood
      @RowanMerewood 4 ปีที่แล้ว

      @@FLUTTERMAD Domain and Path specify requirements for the request with the cookie, SameSite specifies a requirement for the *context* of the request. e.g. Domain can control if the cookies goes to sub1.example.com or sub2.example.com while SameSite specifies if the cookie should go to sub1.example.com when the request comes from another site, like google.com.

  • @lawfirm3843
    @lawfirm3843 3 ปีที่แล้ว

    haha. master

  • @christymathew9035
    @christymathew9035 ปีที่แล้ว

    SUBSCRIBER ++

  • @omarislearning3329
    @omarislearning3329 3 ปีที่แล้ว

    cmd+/