Skip to content

Allow non Same-Site Cookies set on first request - #44574

Open
pointhi wants to merge 1 commit into
nextcloud:masterfrom
pointhi:fix/41210-allow-cookie-set-on-first-request
Open

Allow non Same-Site Cookies set on first request#44574
pointhi wants to merge 1 commit into
nextcloud:masterfrom
pointhi:fix/41210-allow-cookie-set-on-first-request

Conversation

@pointhi

Copy link
Copy Markdown

Summary

When any cookie is already present during the first request (e.g. an Apache module may choose to set it for various reasons) a 412 Precondition Failed error is returned on the first request. The second request works as intended as the Same-Site Cookies are now set correctly.

This breaks for example CalDAV/CardDAV syncs with Davx5 as the request is not retried after the first failure.

The proposed fix is to check for the explicit existence of nc_sameSiteCookielax or nc_sameSiteCookiestrict instead of just checking if any cookie exists. I used the proposed fix from the issue, but I think we can remove count($_COOKIE) > 0 as it looks redundant now.

Checklist

@solracsfsolracsf changed the title Fix #41210 to allow non Same-Site Cookies set on first requestAllow non Same-Site Cookies set on first requestMar 30, 2024
@solracsfsolracsf added this to the Nextcloud 29 milestone Mar 30, 2024
@solracsfsolracsf added the 3. to review Waiting for reviews label Mar 30, 2024
@pointhi
pointhiforce-pushed the fix/41210-allow-cookie-set-on-first-request branch from 37f6382 to 1c28f60CompareApril 1, 2024 12:32
This was referenced Apr 4, 2024
@blizzzblizzz modified the milestones: Nextcloud 29, Nextcloud 30Apr 8, 2024
@github-actions

Copy link
Copy Markdown
Contributor

Hello there,
Thank you so much for taking the time and effort to create a pull request to our Nextcloud project.

We hope that the review process is going smooth and is helpful for you. We want to ensure your pull request is reviewed to your satisfaction. If you have a moment, our community management team would very much appreciate your feedback on your experience with this PR review process.

Your feedback is valuable to us as we continuously strive to improve our community developer experience. Please take a moment to complete our short survey by clicking on the following link: https://cloud.nextcloud.com/apps/forms/s/i9Ago4EQRZ7TWxjfmeEpPkf6

Thank you for contributing to Nextcloud and we hope to hear from you soon!

@thebaron06

Copy link
Copy Markdown

I can confirm that this solution is working and would appreciate this being merged.

@provokateurinprovokateurin left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I understand the idea of the fix and why it is not working correctly at the moment, but I fail to see why this is necessary in the first place. What use-case does this fix? When do you already have a cookie present?

Comment threadlib/base.php
}

if (count($_COOKIE) > 0) {
if (count($_COOKIE) > 0 && (isset($_COOKIE['nc_sameSiteCookielax']) || isset($_COOKIE['nc_sameSiteCookiestrict']))) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
if (count($_COOKIE) > 0 && (isset($_COOKIE['nc_sameSiteCookielax']) || isset($_COOKIE['nc_sameSiteCookiestrict']))) {
if (isset($_COOKIE['nc_sameSiteCookielax']) || isset($_COOKIE['nc_sameSiteCookiestrict'])) {

And adjust the elseif below to be a simple else.

@blizzzblizzz mentioned this pull request Aug 1, 2024
This was referenced Aug 5, 2024
Signed-off-by: Thomas Pointhuber <thomas.pointhuber@gmx.at>
@AndyScherzinger
AndyScherzingerforce-pushed the fix/41210-allow-cookie-set-on-first-request branch from 1c28f60 to 6dbd887CompareAugust 7, 2024 13:44
@skjnldsvskjnldsv mentioned this pull request Aug 13, 2024
@thebaron06

Copy link
Copy Markdown

For me the use-case is to allow the DAVx5 App to sync my contacts and calendars to and AIO instance of nextcloud.
If I understood it correctly, DAVx5 has already a same site cookie set on it's first request and sticks strict to a spec that says: 'don't try again on anything else than a 200 http code' or so. But there exists davx5 issues where this behavior is discussed.

@blizzzblizzz mentioned this pull request Jan 8, 2025
This was referenced Jan 14, 2025
This was referenced Jan 21, 2025
This was referenced Sep 25, 2025
This was referenced Jan 7, 2026
This was referenced Jan 14, 2026
@nextcloud-botnextcloud-bot mentioned this pull request Jan 22, 2026
This was referenced Jan 29, 2026
This was referenced Feb 11, 2026
@blizzzblizzz modified the milestones: Nextcloud 33, Nextcloud 34Feb 16, 2026
@DorraJaouad
DorraJaouad requested a review from a team as a code ownerApril 23, 2026 09:41
@DorraJaouad
DorraJaouad requested review from Altahrim, icewind1991, salmart-dev and sorbaugh and removed request for a teamApril 23, 2026 09:41
@nextcloud-botnextcloud-bot mentioned this pull request May 27, 2026
@nextcloud-botnextcloud-bot mentioned this pull request Jun 4, 2026
This was referenced Jun 5, 2026
@susnuxsusnux added the community pull requests from community label Jun 9, 2026
@susnuxsusnux removed this from the Nextcloud 34.0.1 milestone Jun 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to reviewWaiting for reviewscommunitypull requests from communityfeedback-requestedsecurity

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Same Site Cookies Not Set if First Request has Cookies (412 Precondition Failed)

9 participants

@pointhi@thebaron06@provokateurin@joshtrichards@susnux@blizzz@solracsf@skjnldsv@nextcloud-bot