pub struct Cookies(/* private fields */);Expand description
The request’s cookies; what handlers set goes out with the response.
get/set: plain values the browser can read and change.signed/set_signed: readable, but a changed value reads asNone(HMAC-SHA256).encrypted/set_encrypted: hidden and tamper-proof (AES-256-GCM).
Signed and encrypted cookies use keys derived from SECRET_KEY_BASE;
values made with a key of SECRET_KEY_BASE_PREVIOUS still read. Cookies
Ocre sets are HttpOnly, SameSite=Lax, Path=/, and Secure over
HTTPS. For per-visitor state prefer the Session,
which is encrypted too; use cookies for values that outlive it or that
another part of the site reads (a theme, a “remember me” token).
§Free plan
Nothing billed: cookies travel with the requests.
§Examples
use std::time::Duration;
use ocre::{Cookies, Result};
async fn theme(cookies: Cookies) -> Result<String> {
let theme = cookies.get("theme").unwrap_or_else(|| "light".to_owned());
cookies.set_signed("seen_banner", "1", Some(Duration::from_secs(30 * 86_400)))?;
Ok(theme)
}Implementations§
Source§impl Cookies
impl Cookies
Sourcepub fn get(&self, name: &str) -> Option<String>
pub fn get(&self, name: &str) -> Option<String>
The value of the plain cookie name.
§Examples
async fn theme(cookies: ocre::Cookies) -> String {
cookies.get("theme").unwrap_or_default()
}Sourcepub fn signed(&self, name: &str) -> Result<Option<String>>
pub fn signed(&self, name: &str) -> Result<Option<String>>
The value of the signed cookie name; None when absent or changed by the client.
§Errors
Error::Internal when SECRET_KEY_BASE is missing or shorter than 64 characters.
Sourcepub fn encrypted(&self, name: &str) -> Result<Option<String>>
pub fn encrypted(&self, name: &str) -> Result<Option<String>>
The value of the encrypted cookie name; None when absent or changed by the client.
§Errors
Error::Internal when SECRET_KEY_BASE is missing or shorter than 64 characters.
Sourcepub fn set(
&self,
name: &str,
value: &str,
max_age: Option<Duration>,
) -> Result<()>
pub fn set( &self, name: &str, value: &str, max_age: Option<Duration>, ) -> Result<()>
Sets a plain cookie; max_age None makes it last until the browser closes.
§Errors
Error::Internal for the session cookie’s name, which Ocre manages.
Sourcepub fn set_signed(
&self,
name: &str,
value: &str,
max_age: Option<Duration>,
) -> Result<()>
pub fn set_signed( &self, name: &str, value: &str, max_age: Option<Duration>, ) -> Result<()>
Sets a signed cookie: the browser sees the value, and a changed one reads as None.
§Errors
Error::Internal for the session cookie’s name, or when
SECRET_KEY_BASE is missing or shorter than 64 characters.
Sourcepub fn set_encrypted(
&self,
name: &str,
value: &str,
max_age: Option<Duration>,
) -> Result<()>
pub fn set_encrypted( &self, name: &str, value: &str, max_age: Option<Duration>, ) -> Result<()>
Sets an encrypted cookie: the browser can neither read nor change the value.
§Errors
Error::Internal for the session cookie’s name, or when
SECRET_KEY_BASE is missing or shorter than 64 characters.