i managed to recreate this problem in chrome too, and then fix it
it’s to do with the (any, not just chrome or firefox) browser trusting the url and subsequent cookie handling.
in chrome, if you go to menu > settings > privacy & security, you can customise cookie handling
any security (av etc.) software may also override this behaviour depending on its web protection settings
|