jira/v2/app/iframe endpoint provide Set-Cookie parameter in Response Header without security parameter. For Chrome browser display warning: "This Set-Cookie header didn't specify a “SameSite" attribute and was defaulted to "SameSite=Lax," and was blocked because it came from a cross-site response which was not the response to a top-level navigation. The Set-Cookie had to have been set with “SameSite=None" to enable cross-site usage." So plugin_session cookie is not stored in browser and I'm not able to load images - get request for img has Request header without plugin_session parameter
Hello @Aliaksandr Tsikhanau ,
Thanks for reaching out. I am happy to take a look at this but I am not entirely sure what your working on and have a few questions to get a bigger picture of the error you are encountering.
First, off it sounds like you might be running into an issue similar to what is covered in the following ecosystem report relating to the secure-by-default model for cookies that Chrome released last year:
Can you check this out and see if it lines up, and if so the request is currently waiting for the Atlassian Dev team to follow up on, but if not can you please provide some additional details of what you are doing to trigger the error.
Regards,
Earl
Spend the day sharpening your skills in Atlassian Cloud Organization Admin or Jira Administration, then take the exam onsite. Already ready? Take one - or more - of 12 different certification exams while you’re in Anaheim at Team' 25.
Learn more
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.