Issue with Chrome Updates on “SameSite by default cookies” & “Cookies without SameSite must be secure” with APEX in iFrame
(Doc ID 2652326.1)
Last updated on APRIL 28, 2020
Applies to:Oracle Application Express (APEX) - Version 18.1.0.00.45 and later
Autonomous Database on Shared Infrastructure - Version N/A and later
Information in this document applies to any platform.
Using APEX 18.1 Installled on Oracle Database 12c EE High Perf Release 220.127.116.11.0 - 64bit Production
ORDS Version 18.2.0.r1831332
Trying to launch the APEX application inside ERP as an embedded iFrame in Chrome.
No changes in the APEX configuration, suspect that this could have been caused by Chrome updates on “SameSite by default cookies” & “Cookies without SameSite must be secure”.
Chrome’s update came in February: https://www.chromestatus.com/feature/5088147346030592 and https://www.chromestatus.com/feature/5633521622188032
The issue started occurring after upgrading the Chrome browser settings:
- Go to chrome://flags
- Enabling #same-site-by-default-cookies and #cookies-without-same-site-must-be-secure
The issue is reproducible only when they enable the settings in Chrome as mentioned below:
Chrome updates on “SameSite by default cookies” & “Cookies without SameSite must be secure”.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document