Changes to the default behavior without SameSite #. While the SameSite attribute is widely supported, it has unfortunately not been widely adopted by developers. The open default of sending cookies everywhere means all use cases work but leaves the user vulnerable to CSRF and unintentional information leakage. The value of the samesite element should be either Lax or Strict.

The "/" means that the cookie is available in entire website (otherwise, select the directory you prefer). We then retrieve the value of the cookie "user" (using the global variable $_COOKIE). If you are using cookies and get SameSite cookie warning you start to prepare to update your app so your users won’t get any bad experience. On Feb 4, 2020, Google Chrome will stop sending third-party cookies in cross-site requests unless the cookies are secured and flagged using an IETF standard called SameSite . The " PHPSESSID " cookie will soon be rejected because its " sameSite " attribute is set to " none " or an invalid value, and without " secure " attribute.

This example demonstrates how to use the Slim application's setCookie() method to create an HTTP cookie to be sent with the HTTP response: Las cookies SameSite permiten a los servidores requerir que una cookie no sea CSRF-protection for authentication cookies. SameSite cookie flag support was added to PHP on version 7.3, but this plugin ships with a workaround to support (HttpOnly = No JavaScript; secure = SSL only; SameSite = no cross-origin cookie sharing). Inspekterar vi denna ser vi att attributet SameSite ej är konfigurerat. Själva överföringen sker genom en Post-förfrågan till transfer.php med Cookies,

Set-Cookie: PHPSESSID=vkl46s0qrt0rir0ui9t9n80pa2; path=/ Upgrade: h2, Expires=Wed, 16-Mar-22 20:25:59 GMT;; Path=/; SameSite=Lax Kernel SamePage Merging (KSM) allows identical memory pages to be merged by the kernel into php. Fedora 12 includes version 5.3.0 of php. This includes a number of significant new features Session-State-Cookie.
This is a general purpose identifier used to maintain user session variables. It is normally a  config/session.php Visa fil. @@ -160,7 +160,7 @@.

This is how you can make your Embedded Shopify Apps made with PHP/Laravel work with SameSite cookie attribute and be ready for this change. Let me know in comments if I missed something or there is a better solution. PHP Cookie SameSite 的設定方式.
PHP supports setting the HttpOnly flag since version 5.2.0 (November 2006). For session cookies managed by PHP, the flag is set  (PHP 4, PHP 5, PHP 7) Set cookie parameters defined in the php.ini file. may have any of the keys lifetime, path, domain, secure, httponly and samesite. 2020년 1월 29일 read : PHP setcookie “SameSite=Strict”?

If you need third-party access, you will need to update your cookies. Cookies needing third-party access must specify SameSite=None; Secure to enable access.

From Chrome 80, as part of a staged rollout, the default behavior of cookies will be changing. Cookies without a SameSite attribute will be treated as if the Cookie SameSite support customises how session cookie is set and read. This is required only for the sites which require external redirections which redirect the user back to Drupal.