From 9865e3468d02fc4188c37245936562803e07bc43 Mon Sep 17 00:00:00 2001 From: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com> Date: Wed, 23 Sep 2026 02:04:46 +0000 Subject: [PATCH 1/2] fix(http): handle empty Cookie headers --- http/cookie.ts | 2 +- http/cookie_test.ts | 9 +++++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/http/cookie.ts b/http/cookie.ts index 98d9fc2fe1df..90ca84bfe62b 100644 --- a/http/cookie.ts +++ b/http/cookie.ts @@ -263,7 +263,7 @@ export function getCookies( ): Partial> { const cookie = headers.get("Cookie"); const out: Partial> = Object.create(null); - if (cookie !== null) { + if (cookie) { const c = cookie.split(";"); for (const kv of c) { const [cookieKey, ...cookieVal] = kv.split("="); diff --git a/http/cookie_test.ts b/http/cookie_test.ts index fac04877a33d..705f472074ce 100644 --- a/http/cookie_test.ts +++ b/http/cookie_test.ts @@ -40,6 +40,15 @@ Deno.test({ }, }); +Deno.test("getCookies() handles empty cookie headers", () => { + for (const cookie of ["", " \t "]) { + const headers = new Headers({ Cookie: cookie }); + const cookies = getCookies(headers); + assertEquals(cookies, {}); + assertEquals(Object.getPrototypeOf(cookies), null); + } +}); + Deno.test({ name: "getCookies() has correct types", fn() { From ff38944e6f3087ad5d195d7b9dffade77f81d5f2 Mon Sep 17 00:00:00 2001 From: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com> Date: Fri, 25 Sep 2026 02:18:52 +0000 Subject: [PATCH 2/2] fix(http): ignore empty cookie pairs --- http/cookie.ts | 1 + http/cookie_test.ts | 16 ++++++++++++++++ 2 files changed, 17 insertions(+) diff --git a/http/cookie.ts b/http/cookie.ts index 90ca84bfe62b..6f2cb925de30 100644 --- a/http/cookie.ts +++ b/http/cookie.ts @@ -266,6 +266,7 @@ export function getCookies( if (cookie) { const c = cookie.split(";"); for (const kv of c) { + if (kv.trim() === "") continue; const [cookieKey, ...cookieVal] = kv.split("="); if (cookieKey === "") { throw new SyntaxError("Cookie cannot start with '='"); diff --git a/http/cookie_test.ts b/http/cookie_test.ts index 705f472074ce..4f5c3a231440 100644 --- a/http/cookie_test.ts +++ b/http/cookie_test.ts @@ -49,6 +49,22 @@ Deno.test("getCookies() handles empty cookie headers", () => { } }); +Deno.test("getCookies() ignores empty cookie pairs", () => { + for (const cookie of ["a=1;", "a=1; \t ;", "; a=1", "a=1;;;"]) { + assertEquals(getCookies(new Headers({ Cookie: cookie })), { a: "1" }); + } + assertEquals(getCookies(new Headers({ Cookie: "; ;\t;" })), {}); + assertEquals( + getCookies(new Headers({ Cookie: "a=1; ; b=two ;" })), + { a: "1", b: "two " }, + ); + assertThrows( + () => getCookies(new Headers({ Cookie: "a=1;=invalid;" })), + SyntaxError, + "Cookie cannot start with '='", + ); +}); + Deno.test({ name: "getCookies() has correct types", fn() {