Stop redirects reusing cookies from before the response - #2348
Merged
Merged
Conversation
hyperxpro
force-pushed
the
fix/redirect-stale-cookies
branch
from
September 23, 2026 17:42
dadc504 to
88e04b4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation:
When a redirect keeps the request (GET 301/302, 307, 308), the next hop is built with request.toBuilder(), which copies the request's cookie list. That list already holds the cookie store's values from before the response, so they beat the redirect's own Set-Cookie: a session rotated on the redirect is sent with its old value, a cookie the redirect deleted is sent again, and a Path-scoped cookie follows the redirect to a path it does not match.
Modification:
Reset the cookie list right after toBuilder(), so both branches start without cookies and the store adds back what matches the new URI. The reset that only ran when credentials were stripped is now redundant and goes.
Result:
A redirect sends the cookies its own response left in the store, as 3.0.13 did. RedirectCookieRotationTest covers GET and POST 302, POST 303, 307 and the Path case; all three tests fail without the fix.