|
29 | 29 | */ |
30 | 30 |
|
31 | 31 | import { describe, expect, it } from 'vitest'; |
32 | | -import { parseCookie } from '../../../src/utils/cookie'; |
| 32 | +import { parseCookiePairs } from '../../../src/utils/cookie'; |
33 | 33 |
|
34 | | -describe('parseCookie(str)', function () { |
35 | | - it('should parse cookie string to object', function () { |
36 | | - expect(parseCookie('foo=bar')).toEqual({ foo: 'bar' }); |
37 | | - expect(parseCookie('foo=123')).toEqual({ foo: '123' }); |
| 34 | +describe('parseCookiePairs(value)', function () { |
| 35 | + it('should parse cookie string to ordered pairs', function () { |
| 36 | + expect(parseCookiePairs('foo=bar')).toEqual([['foo', 'bar']]); |
| 37 | + expect(parseCookiePairs('foo=123')).toEqual([['foo', '123']]); |
| 38 | + expect(parseCookiePairs('foo=bar; baz=raz')).toEqual([ |
| 39 | + ['foo', 'bar'], |
| 40 | + ['baz', 'raz'], |
| 41 | + ]); |
38 | 42 | }); |
39 | 43 |
|
40 | 44 | it('should ignore OWS', function () { |
41 | | - expect(parseCookie('FOO = bar; baz = raz')).toEqual({ FOO: 'bar', baz: 'raz' }); |
| 45 | + expect(parseCookiePairs('FOO = bar; baz = raz')).toEqual([ |
| 46 | + ['FOO', 'bar'], |
| 47 | + ['baz', 'raz'], |
| 48 | + ]); |
42 | 49 | }); |
43 | 50 |
|
44 | 51 | it('should parse cookie with empty value', function () { |
45 | | - expect(parseCookie('foo= ; bar=')).toEqual({ foo: '', bar: '' }); |
| 52 | + expect(parseCookiePairs('foo= ; bar=')).toEqual([ |
| 53 | + ['foo', ''], |
| 54 | + ['bar', ''], |
| 55 | + ]); |
46 | 56 | }); |
47 | 57 |
|
48 | 58 | it('should URL-decode values', function () { |
49 | | - expect(parseCookie('foo="bar=123456789&name=Magic+Mouse"')).toEqual({ foo: 'bar=123456789&name=Magic+Mouse' }); |
| 59 | + expect(parseCookiePairs('foo="bar=123456789&name=Magic+Mouse"')).toEqual([ |
| 60 | + ['foo', 'bar=123456789&name=Magic+Mouse'], |
| 61 | + ]); |
50 | 62 |
|
51 | | - expect(parseCookie('email=%20%22%2c%3b%2f')).toEqual({ email: ' ",;/' }); |
| 63 | + expect(parseCookiePairs('email=%20%22%2c%3b%2f')).toEqual([['email', ' ",;/']]); |
52 | 64 | }); |
53 | 65 |
|
54 | 66 | it('should return original value on escape error', function () { |
55 | | - expect(parseCookie('foo=%1;bar=bar')).toEqual({ foo: '%1', bar: 'bar' }); |
| 67 | + expect(parseCookiePairs('foo=%1;bar=bar')).toEqual([ |
| 68 | + ['foo', '%1'], |
| 69 | + ['bar', 'bar'], |
| 70 | + ]); |
56 | 71 | }); |
57 | 72 |
|
58 | | - it('should ignore cookies without value', function () { |
59 | | - expect(parseCookie('foo=bar;fizz ; buzz')).toEqual({ foo: 'bar' }); |
60 | | - expect(parseCookie(' fizz; foo= bar')).toEqual({ foo: 'bar' }); |
| 73 | + it('should keep duplicate cookies as ordered pairs', function () { |
| 74 | + expect(parseCookiePairs('foo=%1;bar=bar;foo=boo')).toEqual([ |
| 75 | + ['foo', '%1'], |
| 76 | + ['bar', 'bar'], |
| 77 | + ['foo', 'boo'], |
| 78 | + ]); |
61 | 79 | }); |
62 | 80 |
|
63 | | - it('should ignore duplicate cookies', function () { |
64 | | - expect(parseCookie('foo=%1;bar=bar;foo=boo')).toEqual({ foo: '%1', bar: 'bar' }); |
65 | | - expect(parseCookie('foo=false;bar=bar;foo=tre')).toEqual({ foo: 'false', bar: 'bar' }); |
66 | | - expect(parseCookie('foo=;bar=bar;foo=boo')).toEqual({ foo: '', bar: 'bar' }); |
| 81 | + it('should return nameless segments with an empty name', function () { |
| 82 | + expect(parseCookiePairs('foo=bar;fizz ; buzz')).toEqual([ |
| 83 | + ['foo', 'bar'], |
| 84 | + ['', 'fizz'], |
| 85 | + ['', 'buzz'], |
| 86 | + ]); |
| 87 | + expect(parseCookiePairs(' fizz; foo= bar')).toEqual([ |
| 88 | + ['', 'fizz'], |
| 89 | + ['foo', 'bar'], |
| 90 | + ]); |
| 91 | + }); |
| 92 | + |
| 93 | + it('should split on ";" even without a trailing space', function () { |
| 94 | + expect(parseCookiePairs('foo=bar;baz=raz')).toEqual([ |
| 95 | + ['foo', 'bar'], |
| 96 | + ['baz', 'raz'], |
| 97 | + ]); |
| 98 | + }); |
| 99 | + |
| 100 | + it('should skip empty segments', function () { |
| 101 | + expect(parseCookiePairs('foo=bar;;;baz=raz;')).toEqual([ |
| 102 | + ['foo', 'bar'], |
| 103 | + ['baz', 'raz'], |
| 104 | + ]); |
| 105 | + expect(parseCookiePairs('')).toEqual([]); |
| 106 | + }); |
| 107 | + |
| 108 | + it('should only split on the first "="', function () { |
| 109 | + expect(parseCookiePairs('data=base64==')).toEqual([['data', 'base64==']]); |
| 110 | + }); |
| 111 | + |
| 112 | + it('should accept an array of header values', function () { |
| 113 | + expect(parseCookiePairs(['foo=bar', 'baz=raz'])).toEqual([ |
| 114 | + ['foo', 'bar'], |
| 115 | + ['baz', 'raz'], |
| 116 | + ]); |
| 117 | + expect(parseCookiePairs(['foo=bar', '', 'baz=raz'])).toEqual([ |
| 118 | + ['foo', 'bar'], |
| 119 | + ['baz', 'raz'], |
| 120 | + ]); |
| 121 | + }); |
| 122 | + |
| 123 | + describe('Set-Cookie mode', function () { |
| 124 | + it('should only parse the first segment of each value', function () { |
| 125 | + expect(parseCookiePairs('sid=1; Max-Age=3600; Path=/', true)).toEqual([['sid', '1']]); |
| 126 | + expect(parseCookiePairs('theme=dark; Expires=Wed, 21 Oct 2026 07:28:00 GMT; Domain=example.com', true)).toEqual([ |
| 127 | + ['theme', 'dark'], |
| 128 | + ]); |
| 129 | + }); |
| 130 | + |
| 131 | + it('should parse one cookie per array value', function () { |
| 132 | + expect(parseCookiePairs(['theme=dark; HttpOnly', 'session=abc123; Secure'], true)).toEqual([ |
| 133 | + ['theme', 'dark'], |
| 134 | + ['session', 'abc123'], |
| 135 | + ]); |
| 136 | + }); |
| 137 | + |
| 138 | + it('should return nameless first segments with an empty name', function () { |
| 139 | + expect(parseCookiePairs('auth_required; HttpOnly', true)).toEqual([['', 'auth_required']]); |
| 140 | + }); |
| 141 | + }); |
| 142 | + |
| 143 | + describe('Set-Cookie attribute handling', function () { |
| 144 | + it('should drop known Set-Cookie attributes by name', function () { |
| 145 | + expect(parseCookiePairs('sid=1; Max-Age=3600; Path=/')).toEqual([['sid', '1']]); |
| 146 | + expect(parseCookiePairs('theme=dark; Expires=Wed, 21 Oct 2026 07:28:00 GMT; Domain=example.com')).toEqual([ |
| 147 | + ['theme', 'dark'], |
| 148 | + ]); |
| 149 | + expect(parseCookiePairs('a=1; SameSite=Lax; Max-Age=60')).toEqual([['a', '1']]); |
| 150 | + }); |
| 151 | + |
| 152 | + it('should return bare flag attributes as nameless pairs (dropped or filtered downstream)', () => { |
| 153 | + expect(parseCookiePairs('a=1; Secure; HttpOnly')).toEqual([ |
| 154 | + ['a', '1'], |
| 155 | + ['', 'Secure'], |
| 156 | + ['', 'HttpOnly'], |
| 157 | + ]); |
| 158 | + }); |
| 159 | + |
| 160 | + it('should match attribute names case-insensitively', function () { |
| 161 | + expect(parseCookiePairs('sid=1; max-age=3600; PATH=/')).toEqual([['sid', '1']]); |
| 162 | + }); |
67 | 163 | }); |
68 | 164 | }); |
0 commit comments