Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Cookie's expire value malformed in actionpack-2.3.2

#2480

This bug makes it impossible to set a cookie expiry date for WebKit browsers, including Safari and MobileSafari on the iPhone.

Captured headers from two different Rails installations:

  • Rails 2.2: expires=Sat, 25 Apr 2009 00:29:23 GMT
  • Rails 2.3: expires=Mo, 11-Apr-2011 00:28:51 GMT

The value for expires in Rails 2.2 is being generated in actionpack-2.2.2 lib/action_controller/cookies.rb line 101:


cookie = CGI::Cookie.new(options)

In Rails 2.3 it's apparently being generated in actionpack-2.3.2 lib/action_controller/vendor/rack-1.0/rack/response.rb lines 63-64:


expires = "; expires=" + value[:expires].clone.gmtime.
  strftime("%a, %d-%b-%Y %H:%M:%S GMT")    if value[:expires]

The dashes between day, month and year in the latter code lead to a value which is not being parsed correctly by WebKit browsers. The value is being ignored and the cookie has no expiry date assigned.

Reported by Stephan Seidt · April 11th, 2009 @ 01:44 AM

State: invalid
Milestone: 2.x
Assigned to: nobody
Importance: none

Activity

  1. Stephan Seidt
    Stephan Seidt

    Please close this ticket, it's a Rack-issue if its any issue at all. The problem does not stem from the dashes but from localization code which was executed before the cookie is being set.

    April 21st, 2009 @ 11:33 PM

  2. CancelProfileIsBroken
    CancelProfileIsBroken
    • State changed from new to invalid

    April 22nd, 2009 @ 12:29 AM

  3. Johan Sørensen
    Johan Sørensen

    Stephen Seidt: could you elaborate on the source of the problem (localization code)? This very issue is bugging me right now…

    April 28th, 2009 @ 12:35 PM

  4. Stephan Seidt
    Stephan Seidt

    Sure, in config/environment.rb we included a file that was monkeypatching several constants in the Date and Time classes (e.g. Date::ABBR_DAYNAMES was responsible for the cookie not being accepted) and the Time#strftime method. After the evil code had been removed cookies were working for webkit browsers again.

    April 28th, 2009 @ 12:42 PM