← All tasks
javascriptkoajs/koa #1561Not a task: already works

Koa should strip quotes for returned cookie values

envgap__koajs__koa-1561

01 / FAILURE SIGNATURE

As reported upstream

In this case, `ctx.cookies.get("my_value_b")` returns `"abc:def:xyz"` rather than `abc:def:xyz` (no quotes), which is not developer friendly and error-prone when dealing with cookies from other web frameworks.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
f9f7714e9528cb02f61ae7d8c8da09b502f88d69
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

koajs/koa #1561 · read the original issue
Some web framework sometimes uses "quoted-string" as defined in [RFC 2965](https://www.ietf.org/rfc/rfc2965.txt) as a cookie value and it causes web browsers to send a header like `Cookie: my_value_a=x; my_value_b="abc:def:xyz";`.



In this case, `ctx.cookies.get("my_value_b")` returns `"abc:def:xyz"` rather than `abc:def:xyz` (no quotes), which is not developer friendly and error-prone when dealing with cookies from other web frameworks.



Since both Django and Express are automatically stripping quotes under the hood (see [this PR](https://github.com/pillarjs/cookies/pull/140) for details), I think koa should also automatically strip quotes for cookie values.



## Possible solutions

* I created [a PR for `cookies` npm package](https://github.com/pillarjs/cookies/pull/140), which is used in koa. If this gets accepted, we can just [bump up the version of `cookies` npm package](https://github.com/koajs/koa/blob/698ce0afbfac6480400625729a4b8fc4b4203fdc/package.json#L38).

* Otherwise, we might need to "fix" it in koa project.



Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]