THIS FIELD NOTICE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTY OF MERCHANTABILITY. YOUR USE OF THE INFORMATION ON THE FIELD NOTICE OR MATERIALS LINKED FROM THE FIELD NOTICE IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS FIELD NOTICE AT ANY TIME.
Revision | Publish Date | Comments |
---|---|---|
1.0 |
30-Mar-20 |
Initial Release |
Affected OS Type | Affected Software Product | Affected Release | Affected Release Number | Comments |
---|---|---|---|---|
NON-IOS |
Finesse Software |
12 |
12.0(1) |
Defect ID | Headline |
---|---|
CSCvs73491 | Chrome 80 breaks Cisco Finesse Single Sign-On APIs for third-party integrations |
Google Chrome 80, which was released by Google in February 2020, changes the default behavior of cookies in cross-domain scenarios (SameSite).
chrome://flags/#same-site-by-default-cookies Default will be Enabled
https://blog.chromium.org/2019/10/developers-get-ready-for-new.html
This change in Google Chrome breaks the Cisco Finesse Single Sign-On implementation for third-party integrations.
Our connector is loaded in an iframe within a different domain and uses the Cisco Finesse Single Sign-On APIs to fetch and refresh a Finesse Rest API access token. Cisco Finesse does not set the SameSite attribute on their SSO token cookies. In Chrome 80, the default behavior for cookies that do not have a SameSite attribute changes from 'None' to 'Lax'. Therefore the cookies are no longer sent in a cross-domain request. However, this is required for third-party integration.
IDS should set the SameSite attribute to 'None' in order to maintain this functionality.
Chrome 80 changes the default value for the Samesite cookie attribute from 'None' to 'Lax'. The result is that the browser does not send cookies without the SameSite attribute in many cross-site request scenarios.
Status tracking for this Chrome feature can be found here:
https://www.chromium.org/updates/same-site
https://www.chromestatus.com/feature/5088147346030592
Upgrade Chrome to version 80 on Client Machine connecting to Finesse 11.6 or 12.0 or 12.5 with IDS
https://software.cisco.com/download/home/283613135/type/284259728/release/12.0(1)ES3
If you require further assistance, or if you have any further questions regarding this field notice, please contact the Cisco Systems Technical Assistance Center (TAC) by one of the following methods:
My Notifications—Set up a profile to receive email updates about reliability, safety, network security, and end-of-sale issues for the Cisco products you specify.
Unleash the Power of TAC's Virtual Assistance