We often get confused how Samesite affects cookies in differen | Hack3rScr0lls
We often get confused how Samesite affects cookies in different attacks in modern browsers. So, we have made a memo and now share it with you.
UPD:
Safari blocks third-party cookies (https://webkit.org/blog/10218/full-third-party-cookie-blocking-and-more/), therefore restrictions in cases of "None" and "No attribute" are related to this and not samesite.
But classic CSRF POST form still works
#SameSite #Cookies #CSRF