Feature request: Cookie prefixes

Open
#2,968 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Stale
Tech stack
python

Research direction

The issue names the set_cookie entry point but no file or test. Start by locating set_cookie and reviewing its existing cookie handling; clarify whether prefix mismatches should raise errors or set attributes automatically, and how the opt-in behavior should work. Done means the chosen behavior is implemented and covered by tests.

Written by the indexing model from the issue text.

Description

web

Browsers will reject cookies named with special prefixes unless corresponding conditions are met (for reference, https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#Cookie_prefixes):

  • __Host-
    If a cookie name has this prefix, it is accepted in a Set-Cookie header only if it is also marked with the Secure attribute, was sent from a secure origin, does not include a Domain attribute, and has the Path attribute set to /. In this way, these cookies can be seen as "domain-locked".
  • __Secure-
    If a cookie name has this prefix, it is accepted in a Set-Cookie header only if it is marked with the Secure attribute and was sent from a secure origin. This is weaker than the __Host- prefix.

While it is unlikely for someone to stumble upon this accidentally, this means that an otherwise-valid cookie (like self.set_cookie('__Secure-name', 'value')) will fail to work for no apparent reason. It might be nice to have some out-of-the-box support for these cookie prefixes.

Maybe set_cookie could raise an exception if there is a mismatch between the cookie name and the domain, path, and secure kwargs. Or the appropriate values could be set within set_cookie according to the prefix. Either way, this behavior could be enabled/disabled by a keyword argument to set_cookie.

Dominant language
Python
Stars
22.2k
Forks
5.6k
Avg merge
3h 42m
Merged PRs (30d)
16

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from tornadoweb/tornado

All issues in tornadoweb/tornado

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.