Skip to main content

Crate web_faith_cookies

Crate web_faith_cookies 

Source
Expand description

A cookie jar for HTTP clients, specialised for the server-side context.

Cookies, as specified in RFC 6265 and 6265bis, are for browsers. Not all of the standard requirements apply to a server context. This jar implements browser-like behaviour, except where it doesn’t make sense. Notably:

  • SameSite is parsed but never acted on. It governs cross-site behaviour, which needs a first-party context to be cross-site from.
  • The public suffix list is not consulted, so a Domain that is a public suffix is not rejected on that ground. A server-side caller talks to origins it chose.
  • A secure transport is https, rather than the wider “potentially trustworthy” origin browsers accept. A __Host- cookie a browser would keep on http://localhost is rejected here.

§Example

use url::Url;
use web_faith_cookies::{CookieLimits, FaithJar};

let jar = FaithJar::new(CookieLimits::default());
let url = Url::parse("https://example.com/")?;

jar.add_cookie_str("session=abc; Path=/", &url);

let header = jar.request_cookie_header(&url).expect("a cookie to send");
assert_eq!(header.to_str()?, "session=abc");

§Features

The reqwest feature enables support to use this jar with reqwest::ClientBuilder.

Structs§

CookieLimits
The limits a jar enforces.
FaithJar
A cookie jar.

Enums§

CookieRejected
Why a cookie was not stored.

Constants§

DEFAULT_MAX_AGE
A cookie may not persist beyond this by default. RFC 6265bis §5.5.
DEFAULT_MAX_PER_HOST
Default limit on cookies kept for one domain.
DEFAULT_MAX_SIZE
Default limit on one cookie’s name plus value, in bytes.
DEFAULT_MAX_TOTAL
Default limit on cookies kept across the whole jar.