reisub

reisub

HttpCookie - standards-compliant HTTP Cookie implementation for Elixir

I just released version 0.8.0 of HttpCookie, a standards-compliant (client-side) HTTP Cookie implementation.

It’s not a new library, but this release resolves the public suffix dependency mess so I thought it’s a good time to spread the word.

The code is tested against implementation-agnostic IETF test cases so I’m reasonably sure the code is correct and I’ve been using it in prod for about a year without issue.

I tried to make it safe by default:

  • there’s default limits for the cookie size and number of cookies per domain and in total
  • there’s a check to reject ‘supercookies’

It also ships with a Req plugin which makes it easy to use if you already use Req.

So you can really use it at 3 different abstraction levels:

  • as a Req plugin
  • as a cookie jar with any other HTTP client
  • as a cookie string parser (if you have niche needs and/or you want to build you own cookie jar)

Contributions in any form or shape are welcome, and I’d be happy to receive bug reports, feature suggestions and PRs. The standard disclaimers apply - this is a free time project and your contributions might not get noticed/reacted to very quickly.

Backstory

Back in late 2023 I needed to access an API that uses cookies for authentication, so I needed a cookie jar to use with Req.
I found two potential libraries to use: cookie_monster and cookie_jar.

I first tried cookie_jar because it was closer to what I needed, but it failed to parse some cookies I had to deal with and upon further inspection I saw that the cookies were probably following the spec (I didn’t know the spec that well yet at that point).

So then I tried to parse the cookies with cookie_monster and that worked for the most part, except I also found it diverged from the spec when handling unsupported attributes which broke parsing one of the cookies I had to deal with.

I was in time crunch with the functionality that used this so for the time being I ended up with a frankenstein solution of:

  1. preprocessing the cookie string to remove the ‘Version’ attribute that one of the servers was sending
  2. parsing the cookie with cookie_monster
  3. storing/using it with cookie_jar

Though the issue with the unrecognized attribute parsing was later resolved in cookie_monster I still thought the Elixir ecosystem could use a client-side cookie implementation that more closely followed the spec.

This is not a complaint about the existing libraries and I’m grateful they exist, but I chose to start over and treat this as a learning opportunity. I definitely learned a lot reading the 3 existing RFCs that cover this functionality and being able to experiment freely helped me get to something I feel works well.

Future work

A new cookie RFC that will obsolete RFC6265 is in the works.

It standardizes SameSite which is already implemented by browsers and removes the deprecated Cookie2/Set-Cookie2 headers, so apart from any bugfixes that’s what you can expect implemented in the future - though I might wait for the standard to be finalized to start.

Most Liked

reisub

reisub

I’ve released v0.8.1 recently, as someone needed Elixir 1.14 support - now the lib works for Elixir 1.14+ (previously it was 1.15+).

See full changelog.

Please keep the feedback coming - I want to make HttpCookie all you need for cookie handling on the client side in Elixir. I think it’s already feature complete, but I’d like to get more people using it to find any edge cases or missing functionality.

Where Next?

Popular in Libraries Top

blatyo
https://www.conduitframework.com/ The best overview for how things are tied together is this presentation. Modules and functions are pre...
New
mhanberg
I just released the first version of Temple: an HTML DSL for Elixir and Phoenix! You can read this blog post or the docs for more info...
New
wmnnd
Hi there, for my project DBLSQD, I needed a file storage solution that is a bit more flexible than Arc. Because I thought others might f...
New
benlime
I created a new library GitHub - benvp/ex_cva: Class Variance Authority for Elixir which aims to make it very easy to define different va...
New
mathieuprog
Hello :wave: Allow me to introduce you to Tz, an alternative time zone database support to Tzdata. Why another library? First and fore...
New
kelvinst
Hey everyone! Well, we made this lib a while ago and now we decided to finally go out and public with it! It’s a tool for creating and m...
New
tmbb
PhoenixWS - Websockets over Phoenix Channels Source code on Github here: https://github.com/tmbb/phoenix_ws Phoenix channels are a great...
New
msaraiva
Surface is an experimental library built on top of Phoenix LiveView and its new LiveComponent API that aims to provide a more declarative...
564 42633 214
New
maltoe
Hello! Came here to announce ChromicPDF, a pet project PDF generator I’ve been working on for the past few months. Why another PDF gener...
New
bluzky
You may know https://ui.shadcn.com/, a UI component library for React. I really love it’s design style and components. I’ve built some co...
381 12391 119
New

Other popular topics Top

Harrisonl
We have an ECS cluster with 4 services, where each task joins a single cluster, via discovery ECS discovery service. Currently when I de...
New
SoCreat
i’m a new one to elixir which editor can i use vs code? or atom? Thanks! :smiley:
New
lessless
I believe there are people here who are dealing with CSV files import on the daily basis, and since Excel is a really popular tool there ...
New
bsollish-terakeet
Credo is smart enough to check for (something like) this: assert length(the_list) == 0 with this response: Checking if an enum is empt...
New
Jim
As a follow up to my earlier question: I have the code compiling and running but not getting a successful login from the rest server. ...
New
aadeshere1
I have a another noob question about loop. Since elixir is immutable, while loop is not directly possible. total = 10 while total != 0 ...
New
chensan
I have a User schema with a :from_id field set to type :string: defmodule TweetBot.Repo.Migrations.CreateUsers do use Ecto.Migration ...
New
qwerescape
Is there a way to get the call stack or stack trace at any point in the code? Not from exceptions, but an expression that returns how the...
New
johnnyicon
Hi all, I've just started learning Elixir and Phoenix Framework, so please pardon my n00bness at this stage. I'm trying to use Postg...
New
lucidguppy
I have a super simple question about elixir - how would I take a file like this foo bar baz and output a new file that enumerates th...
New

Sub Categories:

We're in Beta

About us Mission Statement