# How to make csrf and cookies work inside of an iframe?

**URL:** <https://forum.shopware.com/t/how-to-make-csrf-and-cookies-work-inside-of-an-iframe/71345>\
**Category:** International (English Only)\
**Created:** [3. Dezember 2020 um 12:04 UTC](https://forum.shopware.com/t/how-to-make-csrf-and-cookies-work-inside-of-an-iframe/71345 "2020-12-03T12:04:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![davit\_sargsyan](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@davit\_sargsyan](https://forum.shopware.com/u/davit_sargsyan)\
**Post date:** [3. Dezember 2020 um 12:04 UTC](https://forum.shopware.com/t/how-to-make-csrf-and-cookies-work-inside-of-an-iframe/71345/1 "2020-12-03T12:04:10Z")

</div>

I will be having my website running in an iframe in a different website. When I do so the csrf token is not generated as the cookies are not being set.

I checked the source codes and saw that these options: “SameSite=None; Secure” are not added when shopware creates cookies. How can this be bypassed or fixed?

Extending the jquery plugin is not possible as these are done in statemanager plugin and csrf protection jquery plugin. They cannot be overwritten, can they?

---

<div class="post-metadata">

**Author:** ![brettvormkopp](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/brettvormkopp/32/7788_2.png) [@brettvormkopp](https://forum.shopware.com/u/brettvormkopp)\
**Post date:** [3. Dezember 2020 um 12:09 UTC](https://forum.shopware.com/t/how-to-make-csrf-and-cookies-work-inside-of-an-iframe/71345/2 "2020-12-03T12:09:09Z")

</div>

That is the security behind it. If your iframe have another Host, so the Cookie does.

---

<div class="post-metadata">

**Author:** ![davit\_sargsyan](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@davit\_sargsyan](https://forum.shopware.com/u/davit_sargsyan)\
**Post date:** [3. Dezember 2020 um 12:14 UTC](https://forum.shopware.com/t/how-to-make-csrf-and-cookies-work-inside-of-an-iframe/71345/3 "2020-12-03T12:14:01Z")

</div>

@brettvormkopp‍ so can it be fixed? anything else that can solve the issue that I have?
