Skip to content
logo Knowledgebase

Issues with SameSite cookie behavior in Google Chrome 84 and 91

Created on  | Last modified on 

Summary

Sage 300 experiences issues with SameSite cookie changes in Google Chrome 84 and 91. These changes prevent you from login, payment processing, and Sage CRM integration in Sage 300.

Resolution

▼ What is the change to SameSite cookie behavior?

The Chrome 84 stable release from July 14, 2020 includes a change to cross-domain cookie behavior. The change protects against some classes of cross-site request forgery attacks.

On August 11, 2020, Google enforced the use of SameSite=None-requires-Secure behavior.
▼ What problems does the SameSite cookie behavior change cause?

Here are the problems:

  • In Sage 300 2021, you can’t sign in to web screens
  • You can’t process credit card payments using the Sage 300 Payment Processing program
  • Sage 300 and Sage CRM integration fail when Sage CRM and Sage 300 are on different servers
▼ How do I fix these problems?

Install a fix for Sage 300 in one of the following ways:

  • Install Sage 300 2021.0, 2020.3, or 2019.6. (These product versions include fixes for the problems mentioned above.)
  • If you use Sage 300 2020.2, a hotfix is available for the Sage CRM integration problem. You can download this hotfix from Knowledgebase article 106350.

To fix the problems with Payment Processing and Sage CRM integration, you must complete an extra step. Configure SSL on all Sage 300 and Sage CRM sites.

▼ Is there a workaround if I don’t want to use SSL for Sage 300 and Sage CRM sites?

Yes. You can disable the SameSite flags in your browser:

  1. Open your browser and go to:
  • In Google Chrome: Chrome://flags
  • In Microsoft Edge: Edge://flags
  • In Mozilla Firefox: about:config
  1. Disable SameSite flags as follows:
  • In Chrome or Edge, search for the following flags and set them to Disable:
    • SameSite by default cookies
    • Cookies without SameSite must be secure
  • In Firefox, search for the following flags and set them to False:
    • network.cookie.sameSite.laxByDefault
    • network.cookie.sameSite.noneRequiresSecure
  1. Click Relaunch.
▼ What if I use Microsoft Edge or Mozilla Firefox as my browser?

As of August 24, 2020, this change doesn’t affect Edge or Firefox. However, this change will likely soon be made in these browsers, which is why we’ve included some information about them in the preceding question.

For more information about if this change affects Microsoft Edge, see the following document from Microsoft:

https://docs.microsoft.com/en-us/microsoft-edge/web-platform/site-impacting-changes

▼ Do I need to update my Windows operating system?

Yes. To find Windows updates that support SameSite cookies, see the Microsoft article

https://docs.microsoft.com/en-us/aspnet/samesite/kbs-samesite

Need more help?

Chat now