Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Prevent url encode in response set cookie - nodejs

In my node application, I am trying to change my cookie value with the below code. But when I set some cookie values I see it modified in my response header of browser. Node code :

let nonEncodedString ='s%3A9Q8kumq4BgrHtJPM90ebhhl6OqChsxdp.x0uf93Hk5I03KWeF%2FFT3TM64riv3QAs'
res.cookie('connect.sid', nonEncodedString , { maxAge, httpOnly: true, overwrite: true });

But the header I get is

set-cookie: connect.sid=s%253A9Q8kumq4BgrHtJPM90ebhhl6OqChsxdp.x0uf93Hk5I03KWeF%252FFT3TM64riv3QAs; Max-Age=157680000; Path=/; Expires=Thu, 31 Jul 2025 11:28:35 GMT; HttpOnly

essentially s%3A9Q8kumq4BgrHtJPM90ebhhl6OqChsxdp.x0uf93Hk5I03KWeF%2FFT3TM64riv3QAs is changed to s%253A9Q8kumq4BgrHtJPM90ebhhl6OqChsxdp.x0uf93Hk5I03KWeF%252FFT3TM64riv3QAs. ie. '25' is being added.

I think it's happening because it is getting URL encoded. I don't want that to happen since its changing the value I am sending and I don't have control to parse it before the browser sets it in the cookie.

like image 458
AnandShiva Avatar asked Sep 28 '26 19:09

AnandShiva


1 Answers

you should set an encode function:

  res.cookie('connect.sid', nonEncodedString,
    { maxAge,
      httpOnly: true,
      overwrite: true,
      encode: v => v
    })

the default encode function is encodeURLComponent.

like image 153
MHZT Avatar answered Sep 30 '26 10:09

MHZT



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!