Skip to content

Fix cookie sameSite normalization for browser posting - #64

Merged
ralyodio merged 1 commit into
masterfrom
fix-cookie-samesite
Jul 4, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix-cookie-samesite

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 4, 2026

Copy link
Copy Markdown
Contributor

Bug

Every browser-automated social post (and the new Retry button) was failing at cookie load:

browserContext.addCookies: cookies[1].sameSite: expected one of (Strict|Lax|None)

Playwright's addCookies only accepts sameSite of exactly Strict | Lax | None, but Cookie-Editor / Chrome exports use other spellings — no_restriction, unspecified, lowercase lax/strict, or null. parseCookies passed those through unchanged (it only defaulted when the field was nullish), so any cookie with such a value blew up the whole post.

Fix

normalizeSameSite maps every input to Playwright's enum:

  • strict → Strict
  • none / no_restriction → None
  • lax / unspecified / "" / null / anything else → Lax

It also forces Secure: true on SameSite=None cookies, which Chromium rejects otherwise (a second error you'd hit right after fixing the enum).

Verification

  • tsc --noEmit clean
  • tests/sp/* 32/32, incl. new parse-cookies.test.ts covering the spelling map, the Secure-for-None rule, and the { cookies: [...] } wrapper form

🤖 Generated with Claude Code

Cookie-Editor / Chrome cookie exports use sameSite spellings that
Playwright rejects — "no_restriction", "unspecified", lowercase
"lax"/"strict", or null — causing every browser-automated post to fail at
ctx.addCookies with:
  cookies[N].sameSite: expected one of (Strict|Lax|None)

parseCookies now maps those to Playwright's exact enum (no_restriction →
None, strict → Strict, everything else → Lax) and forces Secure on
SameSite=None cookies, which Chromium rejects otherwise.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 4, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit acf75fb into master Jul 4, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant