Rohith Kumar Ankam

SameSite Cookie

SameSite cookies can help protect websites from CSRF (Cross-Site Request Forgery) attacks, but implementation can be difficult to get right. Here is my testing of various SameSite attributes in Chromium 135.0.7016.0 dev build.

OriginMethodSamesite AttributeCookie sent?
SameGETNone
CrossGETNone
SamePOSTNone
CrossPOSTNone
SameGETLax
CrossGETLax
SamePOSTLax
CrossPOSTLax
SameGETStrict
CrossGETStrict
SamePOSTStrict
CrossPOSTStrict