Skip to content

fix: popouts and reconnects on Safari over http://localhost failed with "Session id mismatch" - #1250

Open
mariobuikhuizen wants to merge 1 commit into
masterfrom
fix/safari-localhost-session-cookie
Open

mariobuikhuizen wants to merge 1 commit into
masterfrom
fix/safari-localhost-session-cookie

Conversation

@mariobuikhuizen

Copy link
Copy Markdown
Contributor

Summary

Reported by the jdaviz team: running jdaviz from the terminal (solara server on http://localhost:<port>) and popping out a viewer gives a spinner, and the console shows ValueError: Session id mismatch.

Cause: Chrome and Firefox accept a Secure cookie from http://localhost, Safari does not (WebKit bug 218980, still open). The server set the session cookie with Secure + SameSite=None on localhost, so Safari never sent it back. The first page load still worked, because a websocket without a cookie falls back to a fresh session id (#379), but a reconnect or an ipypopout popout then reaches the same kernel with a different session id and is refused.

Changes:

  • Over plain http the session cookie is now SameSite=Lax without Secure, on localhost too (starlette and flask). That cookie is still sent to an iframe when the embedding page is on localhost as well (same site, the port does not matter). Over https, directly or via x-forwarded-proto, it stays Secure + SameSite=None so cross-site iframes keep working.
  • A session mismatch that involves a cookieless session is logged as a warning that explains the missing cookie, instead of as a possible hack attempt (related to Misleading 'hack attempt?' log message when session cookie is unavailable #1147).
  • Embed docs updated accordingly.

Supersedes #234.

Tests

  • test_session_cookie_attributes (integration, flask + starlette): plain http gives SameSite=Lax without Secure; x-forwarded-proto: https gives Secure + SameSite=None.
  • test_session_mismatch_without_cookie_is_not_logged_as_hack_attempt (unit).
  • popout_test.py still passes on Chromium. Playwright WebKit cannot run on this machine (missing system libraries), so the Safari behaviour itself was not exercised in a browser here.

🤖 Generated with Claude Code

@maartenbreddels
maartenbreddels temporarily deployed to fix/safari-localhost-session-cookie - solara-stable PR #1250 October 8, 2026 12:14 — with Render Destroyed
@mariobuikhuizen
mariobuikhuizen force-pushed the fix/safari-localhost-session-cookie branch from 42b8797 to 2f063bb Compare October 8, 2026 12:14
…th "Session id mismatch"

Chrome and Firefox accept a Secure cookie from http://localhost, Safari
does not (https://bugs.webkit.org/show_bug.cgi?id=218980). Since the
server set the session cookie with Secure + SameSite=None on localhost,
Safari never sent it back. The first page load worked, because a
websocket without a cookie falls back to a fresh session id, but a
reconnect or an ipypopout popout then reached the same kernel with a
different session id and was refused with "Session id mismatch", leaving
a spinner. This is what jdaviz users hit when running jdaviz from the
terminal.

Over plain http the session cookie is now SameSite=Lax without Secure,
on localhost too. That cookie is still sent to an iframe when the
embedding page is on localhost as well. Over https, directly or via
x-forwarded-proto, it stays Secure + SameSite=None so cross-site iframes
keep working.

A session mismatch that involves a cookieless session is now logged as a
warning that explains the missing cookie, instead of as a possible hack
attempt.

Supersedes #234.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

This branch had an error being deployed

1 failed deployment
fix/safari-localhost-session-cookie - solara-stable PR #1250 — ad76d469 Deployed Oct 8, 2026 by maartenbreddels
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants