Skip to main content

cookie_value

Function cookie_value 

Source
pub fn cookie_value(headers: &HeaderMap) -> Option<String>
Expand description

Reads the session token out of a Cookie header set.

Hand-rolled rather than pulling in axum-extra or cookie for twenty lines. Takes the first match, across all Cookie headers: a crafted request carrying the name twice must not let the second one win, which is a session-fixation vector.