Koa should strip quotes for returned cookie values
envgap__koajs__koa-1561
01 / FAILURE SIGNATURE
As reported upstream
In this case, `ctx.cookies.get("my_value_b")` returns `"abc:def:xyz"` rather than `abc:def:xyz` (no quotes), which is not developer friendly and error-prone when dealing with cookies from other web frameworks.Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
f9f7714e9528cb02f61ae7d8c8da09b502f88d69- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
koajs/koa #1561 · read the original issue
Some web framework sometimes uses "quoted-string" as defined in [RFC 2965](https://www.ietf.org/rfc/rfc2965.txt) as a cookie value and it causes web browsers to send a header like `Cookie: my_value_a=x; my_value_b="abc:def:xyz";`.
In this case, `ctx.cookies.get("my_value_b")` returns `"abc:def:xyz"` rather than `abc:def:xyz` (no quotes), which is not developer friendly and error-prone when dealing with cookies from other web frameworks.
Since both Django and Express are automatically stripping quotes under the hood (see [this PR](https://github.com/pillarjs/cookies/pull/140) for details), I think koa should also automatically strip quotes for cookie values.
## Possible solutions
* I created [a PR for `cookies` npm package](https://github.com/pillarjs/cookies/pull/140), which is used in koa. If this gets accepted, we can just [bump up the version of `cookies` npm package](https://github.com/koajs/koa/blob/698ce0afbfac6480400625729a4b8fc4b4203fdc/package.json#L38).
* Otherwise, we might need to "fix" it in koa project.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]