Session.get() and session.exist() don't work from IE11

I am using Okta to sign in on my asp.net app, from the frontend (javascript)

I am using oktaSignIn.authClient.session.get() when a user lands on the login page to determine if the user has an active session already. If so, it gets the login from the tokenManager and everything goes from there. This works fine on Chrome, but when I run the exact same code on IE11 I always get a 404 response to the ‘/api/v1/sessions/me’ request generated by session.get().

The same thing happens with oktaSignIn.authClient.session.exists().

You can see the code here:

oktaSignIn.authClient.session.get()
            .then(function (session) {
                if (session) {
                    console.log("Welcome back ", session);          
                   //do other stuff
                }
            }).catch(function (err) {
                alert("session.get err");
            })

I captured the relative requests with Fiddler, the chrome request uses a very large cookie with many parameters, whiles the IE11 request uses a cookie with only DT and JSESSIONID.

Again, I am using the exact same code, environment, website, everything for both browsers, and Chrome works while IE11 doesn’t. I’m using windows 10 if that helps, Okta version 3.10 which I downloaded 2 days ago from the official site.

Chrome request:

GET https://<app>/api/v1/sessions/me HTTP/1.1
Host: <app>
Connection: keep-alive
accept: application/json
x-okta-user-agent-extended: okta-signin-widget-3.1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) 
Chrome/76.0.3809.100 Safari/537.36
Sec-Fetch-Mode: cors
content-type: application/json
Origin: https://localhost:44329
Sec-Fetch-Site: cross-site
Referer: https://localhost:44329/login.aspx
Accept-Encoding: gzip, deflate, br
Accept-Language: en-CA,en-GB;q=0.9,en-US;q=0.8,en;q=0.7
Cookie: _ga=GA1.2.299343519.1556126164; _mkto_trk=id:380-NLU-416&token:_mch-okta.com-1556126170097-95899; _fbp=fb.1.1556126170188.1255283656; __cfduid=d4bc80a70e95a34277bd40cb12b1a55b61556128301; _okta_session_attribution={%22utm_page%22:%22/signup/%22%2C%22utm_date%22:%2204/24/2019%22}; _okta_original_attribution={%22utm_page%22:%22/signup/%22%2C%22utm_date%22:%2204/24/2019%22}; _vwo_uuid_v2=D24A9891BC1B5DBFB83C8D30B74195AED|d0c27c99cf1e95126dee34c74f86a0ff; _vis_opt_test_cookie=1; _vwo_uuid=D24A9891BC1B5DBFB83C8D30B74195AED; t=default; DT=DI0BukMnPlvSBK9qRuXOZEq9A; ln=shutchinson@tero.ca; proximity_ac971d0461233665b6ae061a8c8c1125=MLDl96EEinEVhnLBUzDwufwXUGFyTTMKvCZkqz2vdi+v7RNAIvhrpTVOouR2gFm5lNZkLrHBSn9UJK0x4XrAfChh9JjSiME4wxUvHlDRd0cgyt+SknHpXnGOv+cYLTIJQxo2fqiyDoOOk86VG4veWX21E3zw3RLKVtkQRGjkNi0WYPmfumVerPgbNWaWbh0h; LSKey[c]_gz_sid=1556211976096919; LSKey[c]_gz_taid=1556211976100117; _okta_attribution={%22utm_page%22:%22/live-widget/%22%2C%22utm_date%22:%2205/14/2019%22}; cb_user_id=null; cb_group_id=null; cb_anonymous_id=%22f6b02ef6-abe2-46d2-8728-a2dc57954559%22; _vis_opt_exp_256_combi=1; _gcl_au=1.1.786136061.1565992387; srefresh=1565997018787; mp_73623d035cdabf11e9cfd7580c6d5a97_mixpanel=%7B%22distinct_id%22%3A%20%2200ui51w9fD12jiDBU356%22%2C%22%24initial_referrer%22%3A%20%22https%3A%2F%2Fdev-795467.okta.com%2F%22%2C%22%24initial_referring_domain%22%3A%20%22dev-795467.okta.com%22%2C%22env%22%3A%20%22PROD%22%2C%22New%20User%22%3A%20%22%22%2C%22Application%22%3A%20%22%22%2C%22Edition%22%3A%20%22%22%2C%22SKU%22%3A%20%22%22%2C%22Admin%22%3A%20%22true%22%2C%22OrgType%22%3A%20%22%22%7D; mp_f46f8e1c3b1b293b7bea7dfd682939a6_mixpanel=%7B%22distinct_id%22%3A%20%2216a507d51e6f3-0d6a5c0f99cb53-e323069-1fa400-16a507d51e74cd%22%2C%22%24initial_referrer%22%3A%20%22https%3A%2F%2Fdev-795467.okta.com%2Fuser%2Fnotifications%22%2C%22%24initial_referring_domain%22%3A%20%22dev-795467.okta.com%22%2C%22env%22%3A%20%22PROD%22%7D; _gid=GA1.2.635552549.1566227373; _vwo_ds=3%3Aa_0%2Ct_0%3A0%241556128303%3A70.62207395%3A%3A64_0%2C57_0%2C42_0%2C40_0%2C38_0%2C21_0%2C20_0%2C19_0%2C18_0%3A9_0%2C4_0%2C3_0%2C2_0%3A0; _hp2_id.3356162945=%7B%22userId%22%3A%228753994097065292%22%2C%22pageviewId%22%3A%223295477887743453%22%2C%22sessionId%22%3A%222753589374827871%22%2C%22identity%22%3A%22shutchinson%40tero.ca%22%2C%22trackerVersion%22%3A%224.0%22%2C%22identityField%22%3A%22email%22%2C%22isIdentified%22%3A1%7D; sid=102PZ1ziJZcSGmfJnT7YNspBg; JSESSIONID=49EEB5B94A3C1DC595D7C74C3659D2DF

ie request:

GET https://<app>/api/v1/sessions/me HTTP/1.1
Accept: application/json
content-type: application/json
x-okta-user-agent-extended: okta-signin-widget-3.1.0
Referer: https://localhost:44329/Login.aspx
Accept-Language: en-CA
Origin: https://localhost:44329
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
Host: <app>
Connection: Keep-Alive
Cookie: DT=DI0UHgSPgSEQhmTYrJ-_QSpsg; JSESSIONID=25677C0C041D4C30378A4E1B5827C459