New Chrome SameSite Cookie Policy and Luminate SSO
There's a change coming to Chrome that will begin restricting cookies that aren't setting a SameSite Value: https://digiday.com/media/what-is-chrome-samesite/
It doesn't appear that the Luminate SSO cookies are setting this value. While testing in Chrome with that upcoming feature enabled I was unable to login through one of our integration sites.
Are there plans to support this new Chrome cookie policy?
It doesn't appear that the Luminate SSO cookies are setting this value. While testing in Chrome with that upcoming feature enabled I was unable to login through one of our integration sites.
Are there plans to support this new Chrome cookie policy?
Tagged:
6
Comments
-
Did you make any progress on this Jeremy? I opened a ticket with support yesterday about it but haven't heard anything yet.0
-
Ditto for our Team. Opened a ticket.0
-
Hi everyone - sorry for the radio silence on this thread. The Luminate Online development team plans to have an update to the product to address this by the limited release date from Google (Feb 17th). We'll update here once the changes are made and with what the changes entail.
-John Miller
Product Manager, Luminate Online0 -
Hi John,
Do you have further update with regards to this if we may know what to expect/anticipate.
The JSESSIONID cookie at this time of writing still have no SameSite attribute and value defined and it's been affecting some of our custom workaround solution esp. those that have cross-domain aspect on it.
Let us know and thank you in advance.
regards,
Daniel1 -
Folks -
This change has been rolled out as of the Chrome release on August 11. We're working on determining how we can roll out an update to the samesite attribute that won't impact all sessions that switch between the non-secure (http) and secure (https) channels. As the structure is now this change to the JSESSION cookie attribute can cause the session to be lost when traversing between channels and this will require a more significant change than simply updating the cookie. We're looking to address this as soon as we can, more to come here as we determine the options to resolve this.
-John0 -
Thanks John for the update.
I have a question about the JSESSION impact -- will this / do you foresee that it also affect external site using/calling LO API directly on their end (despite the IP whitelisting and domain whitelisting applied for that external site/domain specified within the Site Options)?
I have seen the effect of this new SameSite policy on iframe mostly at moment where even some S-tag refused to display/render and also S-tag conditional refused to work when it comes / pertinent to logged in session. (i.e. S45 tag, or displaying S1 tag info i.e. S1:cons_id etc).
Appreciate the clarification and help as always!
regards,
Daniel0
Categories
- All Categories
- 6 Blackbaud Community Help
- 213 bbcon®
- 1.4K Blackbaud Altru®
- 403 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 1.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- 15 donorCentrics®
- 360 Blackbaud eTapestry®
- 2.6K Blackbaud Financial Edge NXT®
- 656 Blackbaud Grantmaking™
- 576 Blackbaud Education Management Solutions for Higher Education
- 3.2K Blackbaud Education Management Solutions for K-12 Schools
- 939 Blackbaud Luminate Online® and Blackbaud TeamRaiser®
- 84 JustGiving® from Blackbaud®
- 6.6K Blackbaud Raiser's Edge NXT®
- 3.7K SKY Developer
- 248 ResearchPoint™
- 119 Blackbaud Tuition Management™
- 165 Organizational Best Practices
- 241 Member Lounge (Just for Fun)
- 34 Blackbaud Community Challenges
- 34 PowerUp Challenges
- 3 (Open) PowerUp Challenge: Chat for Blackbaud AI
- 3 (Closed) PowerUp Challenge: Data Health
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Product Update Briefing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports+
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Email Marketing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Gift Management
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Event Management
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Home Page
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Query
- 794 Community News
- 2.9K Jobs Board
- 54 Blackbaud SKY® Reporting Announcements
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)



