What does it mean to "disable SameSite for some components"?

44 Views Asked by At

In the ASP.NET documentation about SameSite cookies, is says (bold mine):

Some forms of authentication like OpenID Connect (OIDC) and WS-Federation default to POST based redirects. The POST based redirects trigger the SameSite browser protections, so SameSite is disabled for these components.

What does it mean that SameSite is disabled for these components? That those cookies are blocked by the browser? Or that the browser protections are somehow disabled?

0

There are 0 best solutions below