Skip to content

Stop redirects reusing cookies from before the response - #2348

Merged
hyperxpro merged 2 commits into
mainfrom
fix/redirect-stale-cookies
Sep 23, 2026
Merged

hyperxpro merged 2 commits into
mainfrom
fix/redirect-stale-cookies

Conversation

@hyperxpro

Copy link
Copy Markdown
Member

Motivation:

When a redirect keeps the request (GET 301/302, 307, 308), the next hop is built with request.toBuilder(), which copies the request's cookie list. That list already holds the cookie store's values from before the response, so they beat the redirect's own Set-Cookie: a session rotated on the redirect is sent with its old value, a cookie the redirect deleted is sent again, and a Path-scoped cookie follows the redirect to a path it does not match.

Modification:

Reset the cookie list right after toBuilder(), so both branches start without cookies and the store adds back what matches the new URI. The reset that only ran when credentials were stripped is now redundant and goes.

Result:

A redirect sends the cookies its own response left in the store, as 3.0.13 did. RedirectCookieRotationTest covers GET and POST 302, POST 303, 307 and the Path case; all three tests fail without the fix.

@hyperxpro
hyperxpro force-pushed the fix/redirect-stale-cookies branch from dadc504 to 88e04b4 Compare September 23, 2026 17:42
@hyperxpro
hyperxpro merged commit 4be8bbc into main Sep 23, 2026
17 checks passed
@hyperxpro
hyperxpro deleted the fix/redirect-stale-cookies branch September 23, 2026 17:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant