skip to content

questions

3

Why must multiple HTTP 'Set-Cookie' response headers never be folded into a single comma-separated header line, and what does that imply for HTTP client library APIs?

level: middleimportance: should knowfreq 34%

basics

~20 s

The Expires attribute uses an HTTP-date that itself contains a comma ('Wed, 09 Jun 2027 10:18:14 GMT'), so comma-joining Set-Cookie values is ambiguous and cannot be split back reliably. Client libraries must expose a get-all-values API; a single getHeader('Set-Cookie') loses cookies or corrupts them.

open as a page

Under RFC 6265, when does a new 'Set-Cookie' replace an existing cookie versus create a second cookie with the same name, and what does the client send if two same-named cookies both match a request?

level: seniorimportance: should knowfreq 30%

basics

~20 s

A cookie's identity is the triple name, Domain, Path. A Set-Cookie matching all three replaces the old value in place, keeping its creation time. Differ in any one and you get a second cookie; both are then sent in the Cookie header, longest path first, and the server cannot tell them apart.

open as a page