Limits on SameSite=None Cookies Missing the Secure Flag in Chrome 80 and Later
0 reputation · 05 Nov 2025, 05:40 UTC
Goal: Verify if Chrome’s SameSite=None; Secure requirement is enforced for cookies set by service‑worker‑generated fetch requests that target a different origin.
Context: The SameSite=None; Secure rule is documented for all request types, but it is unclear whether the enforcement applies when the Set‑Cookie header originates from a service worker rather than from a direct network response, especially when the worker runs under a different security origin.
Uncertainty: Some developers report that cookies appear in document.cookie despite missing Secure, while others see DevTools warnings only for regular XHR/fetch calls.
Questions:
- Does Chrome reject SameSite=None cookies lacking Secure when they are set via a service worker’s fetch?
- Are the warnings visible in the Application → Cookies pane for such cookies?
- Does the behavior differ between Chrome versions 80‑115 and the latest stable?