fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: accept a negative Set-Cookie Max-Age attribute - #5571

Merged
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age
Aug 19, 2026
Merged

fix: accept a negative Set-Cookie Max-Age attribute#5571
tsctx merged 3 commits into
nodejs:mainfrom
arshsmith1:cookie-negative-max-age

Conversation

@arshsmith1

Copy link
Copy Markdown
Contributor

This relates to...

N/A

Rationale

parseUnparsedAttributes in lib/web/cookies/parse.js validates the Max-Age attribute-value with /^\d+$/, applied to the whole value rather than to the remainder after the sign. Any negative Max-Age therefore fails the check and the attribute is dropped from the parsed cookie:

getSetCookies(newHeaders({'set-cookie': 'id=a; Max-Age=-1'}))// [{ name: 'id', value: 'a' }]// should be: [{ name: 'id', value: 'a', maxAge: -1 }]

RFC 6265bis section 5.6.2 is explicit that a leading - is allowed:

If the first character of the attribute-value is neither a DIGIT, nor a "-" character followed by a DIGIT, ignore the cookie-av.

If the remainder of attribute-value contains a non-DIGIT character, ignore the cookie-av.

If delta-seconds is less than or equal to zero (0), let expiry-time be the earliest representable date and time.

The step-1 check at line 193 already accepts - as a first character, and the last step above only has meaning if negative values reach it, so the intent in the surrounding code is the spec behaviour. Max-Age=-1 is the usual way a server expires a cookie, and today that signal is silently lost by getSetCookies().

The generation side is deliberately left alone: validateCookieMaxAge still rejects negatives, which matches the max-age-av = "Max-Age=" non-zero-digit *DIGIT grammar a server must emit. Parsing is permissive, serialising stays strict.

Changes

Relax the digit check to /^-?\d+$/ so a single leading sign is accepted and a non-DIGIT remainder is still ignored. Max-Age=-, --1, -1a, +1 and the empty value all stay ignored, and positive values are unchanged.

Features

N/A

Bug Fixes

  • Set-Cookie: ...; Max-Age=-1 now parses to maxAge: -1 instead of dropping the attribute.

Breaking Changes and Deprecations

N/A

Status

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@mcollina
mcollina requested a review from KhafraDevJuly 20, 2026 10:26
@codecov-commenter

codecov-commenter commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.34%. Comparing base (1383989) to head (55df30d).
⚠️ Report is 50 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #5571 +/- ##
==========================================
- Coverage 93.47% 93.34% -0.13% 
==========================================
Files 110 110 Lines 37560 38778 +1218 ==========================================
+ Hits 35108 36197 +1089 - Misses 2452 2581 +129 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.


// 2. If the remainder of attribute-value contains a non-DIGIT
// character, ignore the cookie-av.
if (!/^\d+$/.test(attributeValue)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please make the following changes to ensure closer adherence to the specifications.

Suggested change
if(!/^\d+$/.test(attributeValue)){
if(/[^\d]/.test(attributeValue.slice(1))){

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, that reads much closer to the spec. I took the remainder check as suggested and also tightened step 1 to the current 6265bis wording (a "-" followed by a DIGIT). Without that, slice(1) lets a bare Max-Age=- and an empty value slip past step 2 and parse to NaN/0, so validating the sign up front keeps them ignored while step 2 stays the clean remainder check you wanted. The existing edge cases and the -1 case all still pass. Pushed in 4403160.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
Comment threadlib/web/cookies/parse.js Outdated
Comment on lines +189 to +190
// 1. If the first character of the attribute-value is neither a DIGIT,
// nor a "-" character followed by a DIGIT, ignore the cookie-av.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please revert this change? This comment block is intended to preserve the exact wording from the specification.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted, the comment block is back to the original spec wording. The code still does the sign-followed-by-digit check but the comment stays verbatim.

Signed-off-by: arshiya tabasum <arshi@bugqore.com>
@tsctx
tsctx merged commit 6de6e9a into nodejs:mainAug 19, 2026
35 of 38 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Aug 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arshsmith1@codecov-commenter@tsctx