With Shopware 5 in particular, problems with cookies frequently arise when the online shop is embedded as an iFrame within the procurement solution.
How can I narrow down the problem?
Open your browser’s developer tools and check the ‘Application’ > ‘Cookies’ section to see if a yellow exclamation mark appears next to the cookie labelled ‘session-’. If this is the case, you can try the following solution.
Setting ‘Secure’ and ‘SameSite=None’ for all cookies
Edit the .htaccess file in the root directory of your shop installation and add the following lines:
Header onsuccess edit Set-Cookie ^(.*)$ $1;Secure;SameSite=None
Header always edit Set-Cookie ^(.*)$ $1;Secure;SameSite=None
Check the plugin settings in Shopware or your shop system; the return address from the shop system can only be changed for One customers and must always be set to www.punchcommerce.de by default
It may be that the HTTP header “X-Frame-Options” or a CSP directive is set by the shop software you are using or by your web server. Please check the web server or shop configuration and adjust it accordingly.
Further information