It's proving surprisingly difficult to research. Here are my notes so far: https://github.com/simonw/public-notes/issues/2
SameSite=Lax is almost but not quite the answer I'm looking for, for a couple of reasons:
- It doesn't protect against attacks from subdomains, since they can trigger requests that use existing Lax cookies. This is a problem because I can never be sure that a future decision won't be made to CNAME helpdesk.mysite.com over to some third party vendor who might themselves have security holes that enable XSS attacks to run against my domain
- SameSite cookie support is at 95.75% global usage. That's not 100% yet. Where security is concerned, I care about that 4.25% of users. https://caniuse.com/same-site-cookie-attribute