Expand description
A cookie jar for HTTP clients, specialised for the server-side context.
Cookies, as specified in RFC 6265 and 6265bis, are for browsers. Not all of the standard requirements apply to a server context. This jar implements browser-like behaviour, except where it doesn’t make sense. Notably:
SameSiteis parsed but never acted on. It governs cross-site behaviour, which needs a first-party context to be cross-site from.- The public suffix list is not consulted, so a
Domainthat is a public suffix is not rejected on that ground. A server-side caller talks to origins it chose. - A secure transport is
https, rather than the wider “potentially trustworthy” origin browsers accept. A__Host-cookie a browser would keep onhttp://localhostis rejected here.
§Example
use url::Url;
use web_faith_cookies::{CookieLimits, FaithJar};
let jar = FaithJar::new(CookieLimits::default());
let url = Url::parse("https://example.com/")?;
jar.add_cookie_str("session=abc; Path=/", &url);
let header = jar.request_cookie_header(&url).expect("a cookie to send");
assert_eq!(header.to_str()?, "session=abc");§Features
The reqwest feature enables support to use this jar with reqwest::ClientBuilder.
Structs§
- Cookie
Limits - The limits a jar enforces.
- Faith
Jar - A cookie jar.
Enums§
- Cookie
Rejected - Why a cookie was not stored.
Constants§
- DEFAULT_
MAX_ AGE - A cookie may not persist beyond this by default. RFC 6265bis §5.5.
- DEFAULT_
MAX_ PER_ HOST - Default limit on cookies kept for one domain.
- DEFAULT_
MAX_ SIZE - Default limit on one cookie’s name plus value, in bytes.
- DEFAULT_
MAX_ TOTAL - Default limit on cookies kept across the whole jar.