The audit noise is partly a classification problem. The localization cookie stores country/language selection, so in your consent or cookie-scanning tool it should sit under strictly necessary/functional, not marketing. That stops it counting as a tracking cookie, even though the missing Secure/SameSite attributes remain a real finding for Shopify to fix. Keep the platform finding separate from theme debt: verify in DevTools > Network that the Set-Cookie response header is served with the document response, before any theme JS runs, and note that no app or Liquid change can add those flags. When you send it to Shopify Support, include the exact header value and store URL so it can be routed to the platform team.
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Updating to latest version of @shopify/koa-shopify-auth does not set SameSite cookie | 13 | 193 | June 18, 2020 | |
| Set a server side cookie on shop domain from Shopify APP | 5 | 277 | July 13, 2022 | |
| 'HttpOnly' Flag Missing from User Management Cookies | 0 | 116 | May 6, 2025 | |
| Localization is returning different location in different browsers | 4 | 118 | March 24, 2022 | |
| How to resolve 'same_site_cookies' error in a custom app? | 0 | 219 | January 10, 2022 |