/usr/share/doc/python2-docs/html/library/
/usr/share/doc/python2-docs/html/library
NameSizeModeActions
2to3.html595070644editdlrm
abc.html258260644editdlrm
aepack.html141640644editdlrm
aetools.html163890644editdlrm
aetypes.html210210644editdlrm
aifc.html250640644editdlrm
al.html186720644editdlrm
allos.html352970644editdlrm
anydbm.html181240644editdlrm
archiving.html100780644editdlrm
argparse.html2636160644editdlrm
array.html318550644editdlrm
ast.html381670644editdlrm
asynchat.html339300644editdlrm
asyncore.html406310644editdlrm
atexit.html184550644editdlrm
audioop.html342520644editdlrm
autogil.html87330644editdlrm
base64.html218620644editdlrm
basehttpserver.html374410644editdlrm
bastion.html117980644editdlrm
bdb.html413950644editdlrm
binascii.html229970644editdlrm
binhex.html113090644editdlrm
bisect.html246660644editdlrm
bsddb.html285890644editdlrm
bz2.html290480644editdlrm
calendar.html417620644editdlrm
carbon.html519980644editdlrm
cd.html300330644editdlrm
cgi.html559220644editdlrm
cgihttpserver.html140260644editdlrm
cgitb.html122630644editdlrm
chunk.html158990644editdlrm
cmath.html283650644editdlrm
cmd.html290420644editdlrm
code.html269590644editdlrm
codecs.html1182580644editdlrm
codeop.html158980644editdlrm
collections.html1476470644editdlrm
colorpicker.html80350644editdlrm
colorsys.html119190644editdlrm
commands.html155160644editdlrm
compileall.html186210644editdlrm
compiler.html758970644editdlrm
configparser.html677510644editdlrm
constants.html139790644editdlrm
contextlib.html227770644editdlrm
cookie.html418540644editdlrm
cookielib.html910320644editdlrm
copy.html130040644editdlrm
copy_reg.html146910644editdlrm
crypt.html106470644editdlrm
crypto.html77610644editdlrm
csv.html764560644editdlrm
ctypes.html2645750644editdlrm
curses.ascii.html248730644editdlrm
curses.html1675010644editdlrm
curses.panel.html158240644editdlrm
custominterp.html80260644editdlrm
datatypes.html180150644editdlrm
datetime.html2534380644editdlrm
dbhash.html168250644editdlrm
dbm.html135070644editdlrm
debug.html107030644editdlrm
decimal.html2223150644editdlrm
development.html148280644editdlrm
difflib.html919750644editdlrm
dircache.html122990644editdlrm
dis.html841560644editdlrm
distribution.html76790644editdlrm
distutils.html101520644editdlrm
dl.html176680644editdlrm
doctest.html1858830644editdlrm
docxmlrpcserver.html175730644editdlrm
dumbdbm.html155490644editdlrm
dummy_thread.html100650644editdlrm
dummy_threading.html89340644editdlrm
easydialogs.html331240644editdlrm
email-examples.html474240644editdlrm
email.charset.html294240644editdlrm
email.encoders.html128470644editdlrm
email.errors.html179520644editdlrm
email.generator.html231410644editdlrm
email.header.html291080644editdlrm
email.html557220644editdlrm
email.iterators.html126230644editdlrm
email.message.html701890644editdlrm
email.mime.html316550644editdlrm
email.parser.html351420644editdlrm
email.utils.html270760644editdlrm
ensurepip.html183270644editdlrm
errno.html402460644editdlrm
exceptions.html636930644editdlrm
fcntl.html262450644editdlrm
filecmp.html239970644editdlrm
fileformats.html96530644editdlrm
fileinput.html270710644editdlrm
filesys.html108660644editdlrm
fl.html565250644editdlrm
fm.html130090644editdlrm
fnmatch.html162580644editdlrm
formatter.html373710644editdlrm
fpectl.html168790644editdlrm
fpformat.html114550644editdlrm
fractions.html248880644editdlrm
framework.html369340644editdlrm
frameworks.html75510644editdlrm
ftplib.html495770644editdlrm
functions.html2056400644editdlrm
functools.html296450644editdlrm
future_builtins.html144770644editdlrm
gc.html284230644editdlrm
gdbm.html178050644editdlrm
gensuitemodule.html125740644editdlrm
getopt.html252800644editdlrm
getpass.html114260644editdlrm
gettext.html849710644editdlrm
gl.html243420644editdlrm
glob.html144300644editdlrm
grp.html113160644editdlrm
gzip.html205760644editdlrm
hashlib.html254670644editdlrm
heapq.html348900644editdlrm
hmac.html143740644editdlrm
hotshot.html201470644editdlrm
htmllib.html276820644editdlrm
htmlparser.html424330644editdlrm
httplib.html709320644editdlrm
i18n.html100470644editdlrm
ic.html186540644editdlrm
idle.html421480644editdlrm
imageop.html160990644editdlrm
imaplib.html585150644editdlrm
imgfile.html127320644editdlrm
imghdr.html122380644editdlrm
imp.html376030644editdlrm
importlib.html89260644editdlrm
imputil.html335630644editdlrm
index.html790880644editdlrm
inspect.html568230644editdlrm
internet.html261380644editdlrm
intro.html93530644editdlrm
io.html1137010644editdlrm
ipc.html165980644editdlrm
itertools.html1253970644editdlrm
jpeg.html137570644editdlrm
json.html736780644editdlrm
keyword.html82100644editdlrm
language.html116870644editdlrm
linecache.html114160644editdlrm
locale.html615760644editdlrm
logging.config.html800450644editdlrm
logging.handlers.html801940644editdlrm
logging.html1102540644editdlrm
mac.html233760644editdlrm
macos.html161290644editdlrm
macosa.html140800644editdlrm
macostools.html168980644editdlrm
macpath.html83860644editdlrm
mailbox.html1711210644editdlrm
mailcap.html141320644editdlrm
markup.html198620644editdlrm
marshal.html194560644editdlrm
math.html440150644editdlrm
md5.html151230644editdlrm
mhlib.html241230644editdlrm
mimetools.html212060644editdlrm
mimetypes.html306340644editdlrm
mimewriter.html160780644editdlrm
mimify.html152790644editdlrm
miniaeframe.html131090644editdlrm
misc.html72360644editdlrm
mm.html95700644editdlrm
mmap.html308320644editdlrm
modulefinder.html180960644editdlrm
modules.html90170644editdlrm
msilib.html578530644editdlrm
msvcrt.html212320644editdlrm
multifile.html262560644editdlrm
multiprocessing.html4145350644editdlrm
mutex.html121470644editdlrm
netdata.html183790644editdlrm
netrc.html140210644editdlrm
new.html131770644editdlrm
nis.html115020644editdlrm
nntplib.html456890644editdlrm
numbers.html406360644editdlrm
numeric.html142920644editdlrm
operator.html936220644editdlrm
optparse.html2501090644editdlrm
os.html2401950644editdlrm
os.path.html434020644editdlrm
ossaudiodev.html455940644editdlrm
othergui.html94030644editdlrm
parser.html425580644editdlrm
pdb.html386030644editdlrm
persistence.html156760644editdlrm
pickle.html1096840644editdlrm
pickletools.html114750644editdlrm
pipes.html196850644editdlrm
pkgutil.html273670644editdlrm
platform.html315990644editdlrm
plistlib.html183440644editdlrm
popen2.html276010644editdlrm
poplib.html243200644editdlrm
posix.html166260644editdlrm
posixfile.html213870644editdlrm
pprint.html322070644editdlrm
profile.html727880644editdlrm
pty.html101950644editdlrm
pwd.html123880644editdlrm
pyclbr.html158120644editdlrm
pydoc.html136500644editdlrm
pyexpat.html808860644editdlrm
python.html128540644editdlrm
py_compile.html119320644editdlrm
queue.html268560644editdlrm
quopri.html127390644editdlrm
random.html427220644editdlrm
re.html1559850644editdlrm
readline.html373830644editdlrm
repr.html217780644editdlrm
resource.html282860644editdlrm
restricted.html123660644editdlrm
rexec.html405660644editdlrm
rfc822.html464080644editdlrm
rlcompleter.html144600644editdlrm
robotparser.html134030644editdlrm
runpy.html219250644editdlrm
sched.html198780644editdlrm
scrolledtext.html97280644editdlrm
select.html440900644editdlrm
sets.html401510644editdlrm
sgi.html103710644editdlrm
sgmllib.html344640644editdlrm
sha.html130620644editdlrm
shelve.html299550644editdlrm
shlex.html350330644editdlrm
shutil.html454540644editdlrm
signal.html340230644editdlrm
simplehttpserver.html203510644editdlrm
simplexmlrpcserver.html377940644editdlrm
site.html268870644editdlrm
smtpd.html135870644editdlrm
smtplib.html470540644editdlrm
sndhdr.html109930644editdlrm
socket.html1164140644editdlrm
socketserver.html764300644editdlrm
someos.html164720644editdlrm
spwd.html111630644editdlrm
sqlite3.html1500140644editdlrm
ssl.html2024530644editdlrm
stat.html345970644editdlrm
statvfs.html113260644editdlrm
stdtypes.html2981440644editdlrm
string.html1202190644editdlrm
stringio.html200610644editdlrm
stringprep.html177290644editdlrm
strings.html159050644editdlrm
struct.html448960644editdlrm
subprocess.html1104470644editdlrm
sun.html72530644editdlrm
sunau.html300110644editdlrm
sunaudio.html192360644editdlrm
symbol.html81400644editdlrm
symtable.html258710644editdlrm
sys.html1109960644editdlrm
sysconfig.html262990644editdlrm
syslog.html197370644editdlrm
tabnanny.html113930644editdlrm
tarfile.html887280644editdlrm
telnetlib.html277820644editdlrm
tempfile.html319030644editdlrm
termios.html173090644editdlrm
test.html570300644editdlrm
textwrap.html301350644editdlrm
thread.html214860644editdlrm
threading.html866550644editdlrm
time.html637980644editdlrm
timeit.html405290644editdlrm
tix.html505820644editdlrm
tk.html265680644editdlrm
tkinter.html843160644editdlrm
token.html209990644editdlrm
tokenize.html206070644editdlrm
trace.html286680644editdlrm
traceback.html409000644editdlrm
ttk.html1085150644editdlrm
tty.html97530644editdlrm
turtle.html2304830644editdlrm
types.html298330644editdlrm
undoc.html246800644editdlrm
unicodedata.html201860644editdlrm
unittest.html2250210644editdlrm
unix.html112230644editdlrm
urllib.html682660644editdlrm
urllib2.html1133800644editdlrm
urlparse.html434740644editdlrm
user.html127070644editdlrm
userdict.html320690644editdlrm
uu.html118100644editdlrm
uuid.html301370644editdlrm
warnings.html509500644editdlrm
wave.html248940644editdlrm
weakref.html388080644editdlrm
webbrowser.html265650644editdlrm
whichdb.html94990644editdlrm
windows.html98170644editdlrm
winsound.html204660644editdlrm
wsgiref.html883840644editdlrm
xdrlib.html330180644editdlrm
xml.dom.html978770644editdlrm
xml.dom.minidom.html432300644editdlrm
xml.dom.pulldom.html138350644editdlrm
xml.etree.elementtree.html1118040644editdlrm
xml.html180070644editdlrm
xml.sax.handler.html418770644editdlrm
xml.sax.html234580644editdlrm
xml.sax.reader.html448020644editdlrm
xml.sax.utils.html160870644editdlrm
xmlrpclib.html691910644editdlrm
zipfile.html622270644editdlrm
zipimport.html227690644editdlrm
zlib.html312300644editdlrm
_winreg.html646310644editdlrm
__builtin__.html110690644editdlrm
__future__.html146880644editdlrm
__main__.html75120644editdlrm
Edit: /usr/share/doc/python2-docs/html/library/cookie.html (41854B)
20.22. Cookie — HTTP state management — Python 2.7.16 documentation

Navigation

  • index
  • modules |
  • next |
  • previous |
  • Python »
  • Python 2.7.16 documentation »
  • The Python Standard Library »
  • 20. Internet Protocols and Support »

20.22. Cookie — HTTP state management¶

Note

The Cookie module has been renamed to http.cookies in Python 3. The 2to3 tool will automatically adapt imports when converting your sources to Python 3.

Source code: Lib/Cookie.py


The Cookie module defines classes for abstracting the concept of cookies, an HTTP state management mechanism. It supports both simple string-only cookies, and provides an abstraction for having any serializable data-type as cookie value.

The module formerly strictly applied the parsing rules described in the RFC 2109 and RFC 2068 specifications. It has since been discovered that MSIE 3.0x doesn’t follow the character rules outlined in those specs and also many current day browsers and servers have relaxed parsing rules when comes to Cookie handling. As a result, the parsing rules used are a bit less strict.

The character set, string.ascii_letters, string.digits and !#$%&'*+-.^_`|~ denote the set of valid characters allowed by this module in Cookie name (as key).

Note

On encountering an invalid cookie, CookieError is raised, so if your cookie data comes from a browser you should always prepare for invalid data and catch CookieError on parsing.

exception Cookie.CookieError¶

Exception failing because of RFC 2109 invalidity: incorrect attributes, incorrect Set-Cookie header, etc.

class Cookie.BaseCookie([input])¶

This class is a dictionary-like object whose keys are strings and whose values are Morsel instances. Note that upon setting a key to a value, the value is first converted to a Morsel containing the key and the value.

If input is given, it is passed to the load() method.

class Cookie.SimpleCookie([input])¶

This class derives from BaseCookie and overrides value_decode() and value_encode() to be the identity and str() respectively.

class Cookie.SerialCookie([input])¶

This class derives from BaseCookie and overrides value_decode() and value_encode() to be the pickle.loads() and pickle.dumps().

Deprecated since version 2.3: Reading pickled values from untrusted cookie data is a huge security hole, as pickle strings can be crafted to cause arbitrary code to execute on your server. It is supported for backwards compatibility only, and may eventually go away.

class Cookie.SmartCookie([input])¶

This class derives from BaseCookie. It overrides value_decode() to be pickle.loads() if it is a valid pickle, and otherwise the value itself. It overrides value_encode() to be pickle.dumps() unless it is a string, in which case it returns the value itself.

Deprecated since version 2.3: The same security warning from SerialCookie applies here.

A further security note is warranted. For backwards compatibility, the Cookie module exports a class named Cookie which is just an alias for SmartCookie. This is probably a mistake and will likely be removed in a future version. You should not use the Cookie class in your applications, for the same reason why you should not use the SerialCookie class.

See also

Module cookielib
HTTP cookie handling for web clients. The cookielib and Cookie modules do not depend on each other.
RFC 2109 - HTTP State Management Mechanism
This is the state management specification implemented by this module.

20.22.1. Cookie Objects¶

BaseCookie.value_decode(val)¶

Return a decoded value from a string representation. Return value can be any type. This method does nothing in BaseCookie — it exists so it can be overridden.

BaseCookie.value_encode(val)¶

Return an encoded value. val can be any type, but return value must be a string. This method does nothing in BaseCookie — it exists so it can be overridden.

In general, it should be the case that value_encode() and value_decode() are inverses on the range of value_decode.

BaseCookie.output([attrs[, header[, sep]]])¶

Return a string representation suitable to be sent as HTTP headers. attrs and header are sent to each Morsel’s output() method. sep is used to join the headers together, and is by default the combination '\r\n' (CRLF).

Changed in version 2.5: The default separator has been changed from '\n' to match the cookie specification.

BaseCookie.js_output([attrs])¶

Return an embeddable JavaScript snippet, which, if run on a browser which supports JavaScript, will act the same as if the HTTP headers was sent.

The meaning for attrs is the same as in output().

BaseCookie.load(rawdata)¶

If rawdata is a string, parse it as an HTTP_COOKIE and add the values found there as Morsels. If it is a dictionary, it is equivalent to:

for k, v in rawdata.items():
    cookie[k] = v

20.22.2. Morsel Objects¶

class Cookie.Morsel¶

Abstract a key/value pair, which has some RFC 2109 attributes.

Morsels are dictionary-like objects, whose set of keys is constant — the valid RFC 2109 attributes, which are

  • expires
  • path
  • comment
  • domain
  • max-age
  • secure
  • version
  • httponly

The attribute httponly specifies that the cookie is only transferred in HTTP requests, and is not accessible through JavaScript. This is intended to mitigate some forms of cross-site scripting.

The keys are case-insensitive.

New in version 2.6: The httponly attribute was added.

Morsel.value¶

The value of the cookie.

Morsel.coded_value¶

The encoded value of the cookie — this is what should be sent.

Morsel.key¶

The name of the cookie.

Morsel.set(key, value, coded_value)¶

Set the key, value and coded_value attributes.

Morsel.isReservedKey(K)¶

Whether K is a member of the set of keys of a Morsel.

Morsel.output([attrs[, header]])¶

Return a string representation of the Morsel, suitable to be sent as an HTTP header. By default, all the attributes are included, unless attrs is given, in which case it should be a list of attributes to use. header is by default "Set-Cookie:".

Morsel.js_output([attrs])¶

Return an embeddable JavaScript snippet, which, if run on a browser which supports JavaScript, will act the same as if the HTTP header was sent.

The meaning for attrs is the same as in output().

Morsel.OutputString([attrs])¶

Return a string representing the Morsel, without any surrounding HTTP or JavaScript.

The meaning for attrs is the same as in output().

20.22.3. Example¶

The following example demonstrates how to use the Cookie module.

>>> import Cookie
>>> C = Cookie.SimpleCookie()
>>> C["fig"] = "newton"
>>> C["sugar"] = "wafer"
>>> print C # generate HTTP headers
Set-Cookie: fig=newton
Set-Cookie: sugar=wafer
>>> print C.output() # same thing
Set-Cookie: fig=newton
Set-Cookie: sugar=wafer
>>> C = Cookie.SimpleCookie()
>>> C["rocky"] = "road"
>>> C["rocky"]["path"] = "/cookie"
>>> print C.output(header="Cookie:")
Cookie: rocky=road; Path=/cookie
>>> print C.output(attrs=[], header="Cookie:")
Cookie: rocky=road
>>> C = Cookie.SimpleCookie()
>>> C.load("chips=ahoy; vienna=finger") # load from a string (HTTP header)
>>> print C
Set-Cookie: chips=ahoy
Set-Cookie: vienna=finger
>>> C = Cookie.SimpleCookie()
>>> C.load('keebler="E=everybody; L=\\"Loves\\"; fudge=\\012;";')
>>> print C
Set-Cookie: keebler="E=everybody; L=\"Loves\"; fudge=\012;"
>>> C = Cookie.SimpleCookie()
>>> C["oreo"] = "doublestuff"
>>> C["oreo"]["path"] = "/"
>>> print C
Set-Cookie: oreo=doublestuff; Path=/
>>> C["twix"] = "none for you"
>>> C["twix"].value
'none for you'
>>> C = Cookie.SimpleCookie()
>>> C["number"] = 7 # equivalent to C["number"] = str(7)
>>> C["string"] = "seven"
>>> C["number"].value
'7'
>>> C["string"].value
'seven'
>>> print C
Set-Cookie: number=7
Set-Cookie: string=seven
>>> # SerialCookie and SmartCookie are deprecated
>>> # using it can cause security loopholes in your code.
>>> C = Cookie.SerialCookie()
>>> C["number"] = 7
>>> C["string"] = "seven"
>>> C["number"].value
7
>>> C["string"].value
'seven'
>>> print C
Set-Cookie: number="I7\012."
Set-Cookie: string="S'seven'\012p1\012."
>>> C = Cookie.SmartCookie()
>>> C["number"] = 7
>>> C["string"] = "seven"
>>> C["number"].value
7
>>> C["string"].value
'seven'
>>> print C
Set-Cookie: number="I7\012."
Set-Cookie: string=seven

Table Of Contents

  • 20.22. Cookie — HTTP state management
    • 20.22.1. Cookie Objects
    • 20.22.2. Morsel Objects
    • 20.22.3. Example

Previous topic

20.21. cookielib — Cookie handling for HTTP clients

Next topic

20.23. xmlrpclib — XML-RPC client access

This Page

  • Show Source

Quick search

Navigation

  • index
  • modules |
  • next |
  • previous |
  • Python »
  • Python 2.7.16 documentation »
  • The Python Standard Library »
  • 20. Internet Protocols and Support »
© Copyright 1990-2019, Python Software Foundation.
The Python Software Foundation is a non-profit corporation. Please donate.
Last updated on Mar 27, 2019. Found a bug?
Created using Sphinx 1.7.6.