The Google Chrome™ 80 release, scheduled for February 2020, changes the default cross-domain (SameSite) behavior of cookies. We’ve examined the impacts to the B2B Commerce managed package and B2B Commerce market templates, and outlined recommended actions for customers to take below.
For more information on Salesforce integration impacts, and when the SameSite changes go into effect, see this Salesforce knowledge article.
Verify that your storefront settings are secure by completing the following steps.
1. Verify that traffic to your community uses a secure connection.
a. In the community’s Site Detail section, confirm that the following options are selected:
i. Require Secure Connections (HTTPS)
ii. Upgrade all requests to HTTPS
NOTE: These options are enabled by default in a new community. If these options aren’t enabled, click Edit, enable them, and then save your changes.
2. Verify that your storefront uses a secure domain name URL.
a. Go to CC Admin | Your storefront | General Settings.
b. For Site Secure Domain, confirm the domain name URL contains https://.
The SameSite changes affect the use of the cookies in any version of the CyberSource for B2B Commerce market template. Previously, we recommended that you use non-embedded endpoint URLs for the Endpoint: Token Create and Endpoint:Transaction configuration setting values. Non-embedded endpoints rely on the cookies to maintain a session when attempting to authenticate a 3DS card within an <iframe>.
If necessary, update your endpoint settings by completing the following steps. Complete these changes any time before February 17, 2020.
|
Configuration Setting |
Environment |
Non-embedded Endpoint URL |
Embedded Endpoint URL |
|
Endpoint: Token Create |
Test |
https://testsecureacceptance.cybersource.com/silent/token/create |
https://testsecureacceptance.cybersource.com/silent/embedded/token/create |
|
Production |
https://secureacceptance.cybersource.com/silent/token/create |
https://secureacceptance.cybersource.com/silent/embedded/token/create | |
|
Endpoint: Transaction |
Test |
https://testsecureacceptance.cybersource.com/silent/embedded/pay | |
|
Production |
https://secureacceptance.cybersource.com/silent/embedded/pay |
000382766

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.