In this post, I dissect a common misconception about the SameSite cookie attribute and I explore its potential impact on Web security.

TL;DR

  • The SameSite cookie attribute is not well understood.
  • Conflating site and origin is a common but