Skip to content

Archive

SameSite

3 articles
Cybersecurity 22 Sep 2026 5 min read

SameSite Cookies Constrain Cross-Site Credential Sending

SameSite Cookies Constrain Cross-Site Credential Sending Cookies are ambient credentials: once a browser stores a cookie that matches a request’s domain, path, security, and expiry rules, application code does not have to add that cookie explicitly to every request. That convenience also creates a security boundary. A page on one site can cause a browser to send requests to another site, and some of those requests may carry cookies. The SameSite attribute gives the browser another condition to evaluate before attaching a cookie. It does not change the cookie’s value or authenticate the request by itself. It controls cookie inclusion according to the relationship between the request context and the cookie’s site.

Cybersecurity 20 Sep 2026 5 min read

SameSite Cookies Make Site Context Part of Session Delivery

SameSite Cookies Make Site Context Part of Session Delivery HTTP cookies are ambient credentials in many web applications. Once a browser stores a session cookie, matching requests can carry it automatically; application code does not have to attach the credential to every request. That convenience also creates a security problem: a page on another site may cause the browser to issue a request to the authenticated application. The SameSite cookie attribute adds request context to the browser’s delivery decision. A cookie can still match its domain, path, expiry, and transport requirements, yet be withheld because the request is cross-site. The control therefore changes where part of the session boundary is enforced: before the credential reaches the server.

Cybersecurity 16 Sep 2026 7 min read

SameSite Cookies Draw a Site Boundary That Is Broader Than Origin

SameSite Cookies Draw a Site Boundary That Is Broader Than Origin Two HTTPS applications can be isolated by the browser’s same-origin policy yet still occupy the same cookie site. A service at accounts.example.com and another at shop.example.com have different origins because their hosts differ, but cookie policy can classify their request context at a broader site boundary. That gap matters when SameSite is treated as if it were equivalent to origin isolation.