# Aflex to fix Chrome 80 Samesite Cookie attribute

**URL:** <https://community.a10networks.com/t/aflex-to-fix-chrome-80-samesite-cookie-attribute/587>\
**Category:** aFleX\
**Created:** [January 30, 2020, 6:53pm UTC](https://community.a10networks.com/t/aflex-to-fix-chrome-80-samesite-cookie-attribute/587 "2020-01-30T18:53:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![colson](https://avatars.discourse-cdn.com/v4/letter/c/9e8a1a/32.png) [@colson](https://community.a10networks.com/u/colson)\
**Post date:** [January 30, 2020, 6:53pm UTC](https://community.a10networks.com/t/aflex-to-fix-chrome-80-samesite-cookie-attribute/587/1 "2020-01-30T18:53:26Z")

</div>

SameSite is making headlines because Google’s Chrome 80 browser will enforce a first-party default on all cookies that don’t have the attribute set. This will lead to repercussions if companies who rely on third-party cookie requests don’t make changes by the February 4 deadline.

[SameSite Cookie Attribute: What It Is And Why It Matters](https://adzerk.com/blog/chrome-samesite/)  
SameSite cookie attributes - what they are and how Google’s Chrome 80 defaults will impact ad tech vendors and publishersSince we have a collaboration portal, we use third-party-cookies. The fix? Set the attribute to Samesite=none. Should be easy but I can’t get it to work on the A10. The syntax is fine, but the rule never triggers. We get 0 hits. Environment below. No other aflex rules are affected and their content does not override the new rule.  
slb virtual-server vip-123.456.78.9-http-cm 205.138.36.4&nbsp;  
&nbsp;port 80 http&nbsp;  
&nbsp;&nbsp;aflex http-https-redirect-w-302&nbsp;  
&nbsp;&nbsp;aflex Remove-all-instances-server-header&nbsp;  
&nbsp;&nbsp;aflex HTTP\_REQUEST&nbsp;  
&nbsp;&nbsp;aflex generic\_samesite\_none&nbsp;  
&nbsp;&nbsp;service-group HTTPS-REDIRECT&nbsp;  
&nbsp;port 443 https&nbsp;  
&nbsp;&nbsp;name \_123.456.78.9\_HTTPS\_443&nbsp;  
&nbsp;&nbsp;access-list name WEB-Subnet source-nat-pool nat-123.456.78.1&nbsp;  
&nbsp;&nbsp;aflex Disable-TLS10&nbsp;  
&nbsp;&nbsp;aflex Remove-all-instances-server-header&nbsp;  
&nbsp;&nbsp;aflex HTTP\_REQUEST&nbsp;  
&nbsp;&nbsp;aflex generic\_samesite\_none&nbsp;  
&nbsp;&nbsp;service-group vip-123.456.78.9-https-serverfarm&nbsp;  
&nbsp;&nbsp;template persist cookie vip-123.456.78.9-https-stickyfarm&nbsp;  
&nbsp;&nbsp;template http NODEJS&nbsp;  
&nbsp;&nbsp;template client-ssl test&nbsp;  
!  
\*\*Rule -syntax is fine but rule just get’s bypassed. Open to any other rule to accomplish the same thing. Or, can someone tell me why the rule won’t trigger?  
&nbsp;when HTTP\_RESPONSE {  
set cookie\_headers [HTTP::header values “Set-Cookie”]  
HTTP::header remove “Set-Cookie”

foreach set\_cookie\_header $cookie\_headers {  
&nbsp;&nbsp;HTTP::header insert “Set-Cookie” “${set\_cookie\_header}; SameSite=None”  
}  
}\*\*

---

<div class="post-metadata">

**Author:** ![mdunn](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@mdunn](https://community.a10networks.com/u/mdunn)\
**Post date:** [January 30, 2020, 7:08pm UTC](https://community.a10networks.com/t/aflex-to-fix-chrome-80-samesite-cookie-attribute/587/2 "2020-01-30T19:08:37Z")

</div>

I’m not an aflex expert, but I do know that if you have multiple aflex scripts bound to a single vPort, they are concatenated together and processed sequentially from top to bottom. Perhaps you have another aflex script triggering on HTTP\_RESPONSE, and you’d need to add this logic to that other script’s HTTP\_RESPONSE section?

---

<div class="post-metadata">

**Author:** ![colson](https://avatars.discourse-cdn.com/v4/letter/c/9e8a1a/32.png) [@colson](https://community.a10networks.com/u/colson)\
**Post date:** [January 30, 2020, 7:15pm UTC](https://community.a10networks.com/t/aflex-to-fix-chrome-80-samesite-cookie-attribute/587/3 "2020-01-30T19:15:51Z")

</div>

Thanks, That is a thought I had not considered. I also wondered if you could change the sequence of Aflex rules but not even sure that is possible. I will investigate. Thank you!

---

<div class="post-metadata">

**Author:** ![colson](https://avatars.discourse-cdn.com/v4/letter/c/9e8a1a/32.png) [@colson](https://community.a10networks.com/u/colson)\
**Post date:** [January 30, 2020, 9:37pm UTC](https://community.a10networks.com/t/aflex-to-fix-chrome-80-samesite-cookie-attribute/587/4 "2020-01-30T21:37:28Z")

</div>

Thank you!!! I owe you a beer or ten. We’ve made some progress. The last item is the persistence cookie itself. I don’t see an option to add the samesite=none attribute. httponly and secure are the only options for the persist template. Any ideas?

 ![cookie_samesite.png](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/6bfd033b4295cd4f58cc0f062f84a4a97bbf0341.png)
