Skip to content

Scope cookies to the host that set them - #2075

Open
rzo1 wants to merge 1 commit into
mainfrom
fix/cookie-host-scope
Open

Scope cookies to the host that set them#2075
rzo1 wants to merge 1 commit into
mainfrom
fix/cookie-host-scope

Conversation

@rzo1

@rzo1 rzo1 commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

CookieConverter only checked applicability for cookies carrying a Domain attribute. A cookie without one, which is the usual session cookie, skipped the check and was sent to whatever host was being fetched. The domain check also passed on exception and accepted a single-label Domain such as com.

A three-argument getCookies taking the originating host is added and both protocol implementations use it. Neither records the host whose response set the cookie, so they pass null for now and a cookie that cannot be scoped is dropped rather than sent: with http.use.cookies enabled, host-only cookies stop going out until that host is recorded at fetch time. The two-argument method is deprecated and kept. Also corrects the metadata.transfer example in internals.adoc, which named set-cookie where the key is protocol.set-cookie.

For all changes

  • Is there a issue associated with this PR? Is it referenced in the commit message? - no issue

  • Does your PR title start with #XXXX where XXXX is the issue number you are trying to resolve? - no issue

  • Has your PR been rebased against the latest commit within the target branch (typically main)?

  • Is your initial contribution a single, squashed commit?

  • Is the code properly formatted with mvn git-code-format:format-code -Dgcf.globPattern="**/*" -Dskip.format.code=false?

For code changes

  • Have you ensured that the full suite of tests is executed via mvn clean verify? - core module tests only
  • Have you written or updated unit tests to verify your changes? - CookieConverterTest extended
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0? - no new dependencies
  • If applicable, have you updated the LICENSE file, including the main LICENSE file? - n/a
  • If applicable, have you updated the NOTICE file, including the main NOTICE file? - n/a

@rzo1 rzo1 added this to the 4.0.0 milestone Aug 27, 2026
CookieConverter only checked the domain when the cookie carried a Domain
attribute, so a cookie without one was sent to any target URL, a single
label Domain such as "com" matched every host under it, and
checkDomainMatchToUrl returned true when it threw. getCookies now takes
the originating URL, keeps a cookie without a Domain attribute for that
host only, rejects single label domains and fails closed on error.

Behaviour change: the protocol does not record the host that set a cookie,
so it passes no origin and cookies without a Domain attribute are no
longer sent. The metadata.transfer example in internals.adoc named
set-cookie instead of protocol.set-cookie and is corrected too.
@rzo1
rzo1 force-pushed the fix/cookie-host-scope branch from 25836d6 to fd5035f Compare August 27, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants