CodeSampleX

Exemple

hono 4.13.7: setCookie

Échantillon vérifié pour npm hono 4.13.7: setCookie. Le contrat s'est exécuté sur node 22 · linux debian/x64 · docker et a réussi.

sha256:f80d60d374e8454d1649d8f0e5da3cbbb4ba3c03bc558d16295cb43cb99d0acf

Ce réseau offre une seule chose : un échantillon qui compile. Il l'a exécuté dans un bac à sable et conservé le reçu signé. Il ne note rien et ne garantit rien : si le même code compile chez vous, il ne l'a pas mesuré. Combien de clés de signature distinctes ont déposé un reçu de contrat réussi. Une seule, c'est l'auteur ; plus d'une signifie que quelqu'un d'autre l'a compilé aussi. Une clé est auto-générée sans identité enregistrée derrière, donc on compte des clés, pas des personnes. MIT-0

Preuves d'exécution

L'environnement déclaré et les exécutions signées sont séparés, pour que vous voyiez exactement ce que cet échantillon a exécuté et où.

Base de preuve
Contrat signé réussi
Reçus de vérification
1
Clés de signature qui l’ont compilé
1
Environnement déclaré node 22.23 linux 24 · ubuntu · glibc 2.39 x64 node 22.23 javascript npm 10

Environnements des exécutions de vérification

Environnement Contrat Étapes Exécution
node 22 · linux debian/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1node:22@sha256:8a34c4ab3ea2…
2026-09-06

Cas

HOW
Objectif
verify setCookie in pkg:npm/hono@4.13.7
Paquets
Symboles
  • setCookie
Environnement
node 22.23.2
Créé
2026-09-06T04:18:54Z

Contrat

  1. hono exports setCookie from hono/cookie entrypoint and version is 4.13.7
  2. setCookie sets Set-Cookie response header with name and URI-encoded value
  3. setCookie configures path, domain, secure, httpOnly, maxAge, sameSite, and expires attributes
  4. setCookie appends multiple cookies to the Set-Cookie response header without overwriting
  5. setCookie supports secure and host prefixes and enforces security attributes

Fichiers

  • PROMPT.md
  • csx.json
  • package-lock.json
  • package.json
  • spec.json
  • test/contract.mjs

Télécharger l’artefact source (tar.gz)

Code source

PROMPT.md
Clean-room public code sample — generation instructions

Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.

A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.

Goal: verify setCookie in pkg:npm/hono@4.13.7
Kind: HOW

Use EXACTLY these public packages and versions:
  - pkg:npm/hono@4.13.7
Demonstrate these symbols/APIs:
  - setCookie

Rules:
  - One focused purpose; the smallest project that proves the goal.
  - Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
  - Pin every dependency with a lockfile so resolution is reproducible.
  - No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
  - No personal names, emails, company names, or project identifiers of any kind.
  - No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
  - Keep it under 200 files and 256KB packed.
csx.json
{"case":{"caseId":"case:sha256:2012f3c4350ff31b63ec2542e5edf1bc2f7998645cad6a57483ce5100cd1c222","contract":["hono exports setCookie from hono/cookie entrypoint and version is 4.13.7","setCookie sets Set-Cookie response header with name and URI-encoded value","setCookie configures path, domain, secure, httpOnly, maxAge, sameSite, and expires attributes","setCookie appends multiple cookies to the Set-Cookie response header without overwriting","setCookie supports secure and host prefixes and enforces security attributes"],"goal":"verify setCookie in pkg:npm/hono@4.13.7","kind":"HOW","packages":["pkg:npm/hono@4.13.7"],"schemaVersion":1,"symbols":["setCookie"]},"contractCommand":["node","test/contract.mjs"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"npm","executionContext":"node","language":"javascript","libc":"glibc","libcVersion":"2.39","moduleSystem":"esm","os":"linux","osVersionBucket":"24","packageManager":"npm","packageManagerVersion":"10.9.8","runtime":"node","runtimeVersion":"22.23.2","schemaVersion":1},"license":"MIT-0","packages":["pkg:npm/hono@4.13.7"],"schemaVersion":1,"subject":"pkg:npm/hono@4.13.7","symbols":["setCookie"],"verifierAdapter":"node-typescript@1"}
package-lock.json
{
  "name": "sample-hono-setcookie",
  "version": "1.0.0",
  "lockfileVersion": 3,
  "requires": true,
  "packages": {
    "": {
      "name": "sample-hono-setcookie",
      "version": "1.0.0",
      "license": "MIT-0",
      "dependencies": {
        "hono": "4.13.7"
      }
    },
    "node_modules/hono": {
      "version": "4.13.7",
      "resolved": "https://registry.npmjs.org/hono/-/hono-4.13.7.tgz",
      "integrity": "sha512-c8/gF9ac8Y78/agExVocyLevgR+JlpNB444Py0FSX8pJoPdYUfUzRcXtYEYGwt6l19qIlVZPN5Mfsw9jFShmQQ==",
      "license": "MIT",
      "engines": {
        "node": ">=16.9.0"
      }
    }
  }
}
package.json
{
  "name": "sample-hono-setcookie",
  "version": "1.0.0",
  "type": "module",
  "private": true,
  "license": "MIT-0",
  "dependencies": {
    "hono": "4.13.7"
  }
}
spec.json
{
  "schemaVersion": 1,
  "goal": "verify setCookie in pkg:npm/hono@4.13.7",
  "kind": "HOW",
  "packages": [
    "pkg:npm/hono@4.13.7"
  ],
  "symbols": [
    "setCookie"
  ]
}
test/contract.mjs
import assert from 'node:assert/strict';
import fs from 'node:fs';
import { fileURLToPath } from 'node:url';
import { Hono } from 'hono';
import { setCookie } from 'hono/cookie';

// Contract 1: hono exports setCookie from hono/cookie entrypoint and version is 4.13.7
{
  const honoEntryUrl = import.meta.resolve('hono');
  const pkgJsonPath = fileURLToPath(new URL('../package.json', honoEntryUrl));
  assert.ok(fs.existsSync(pkgJsonPath));
  const pkgJson = JSON.parse(fs.readFileSync(pkgJsonPath, 'utf8'));
  assert.strictEqual(pkgJson.name, 'hono');
  assert.strictEqual(pkgJson.version, '4.13.7');
  assert.ok(pkgJson.exports['./cookie']);
  assert.strictEqual(typeof setCookie, 'function');
}

// Contract 2: setCookie sets Set-Cookie response header with name and URI-encoded value
{
  const app = new Hono();
  app.get('/basic', (c) => {
    setCookie(c, 'theme', 'dark');
    setCookie(c, 'message', 'hello world');
    return c.text('ok');
  });

  const res = await app.request('http://localhost/basic');
  assert.strictEqual(res.status, 200);
  const cookies = res.headers.getSetCookie();
  assert.strictEqual(cookies.length, 2);
  assert.ok(cookies[0].startsWith('theme=dark; Path=/'));
  assert.ok(cookies[1].startsWith('message=hello%20world; Path=/'));
}

// Contract 3: setCookie configures path, domain, secure, httpOnly, maxAge, sameSite, and expires attributes
{
  const app = new Hono();
  const expiresDate = new Date(Date.now() + 86400 * 1000);
  app.get('/options', (c) => {
    setCookie(c, 'session', 'sess123', {
      path: '/api',
      domain: 'example.com',
      secure: true,
      httpOnly: true,
      maxAge: 3600,
      sameSite: 'Strict',
      expires: expiresDate,
    });
    return c.text('options set');
  });

  const res = await app.request('http://localhost/options');
  assert.strictEqual(res.status, 200);
  const cookieHeader = res.headers.get('set-cookie');
  assert.ok(cookieHeader);
  assert.ok(cookieHeader.includes('session=sess123'));
  assert.ok(cookieHeader.includes('Path=/api'));
  assert.ok(cookieHeader.includes('Domain=example.com'));
  assert.ok(cookieHeader.includes('Secure'));
  assert.ok(cookieHeader.includes('HttpOnly'));
  assert.ok(cookieHeader.includes('Max-Age=3600'));
  assert.ok(cookieHeader.includes('SameSite=Strict'));
  assert.ok(cookieHeader.includes(`Expires=${expiresDate.toUTCString()}`));
}

// Contract 4: setCookie appends multiple cookies to the Set-Cookie response header without overwriting
{
  const app = new Hono();
  app.get('/multiple', (c) => {
    setCookie(c, 'c1', 'v1');
    setCookie(c, 'c2', 'v2');
    setCookie(c, 'c3', 'v3');
    return c.text('done');
  });

  const res = await app.request('http://localhost/multiple');
  assert.strictEqual(res.status, 200);
  const cookies = res.headers.getSetCookie();
  assert.strictEqual(cookies.length, 3);
  assert.ok(cookies.some((c) => c.startsWith('c1=v1')));
  assert.ok(cookies.some((c) => c.startsWith('c2=v2')));
  assert.ok(cookies.some((c) => c.startsWith('c3=v3')));
}

// Contract 5: setCookie supports secure and host prefixes and enforces security attributes
{
  const app = new Hono();
  app.get('/prefixes', (c) => {
    setCookie(c, 'sec', 'val1', { prefix: 'secure' });
    setCookie(c, 'hst', 'val2', { prefix: 'host' });
    return c.text('prefixed');
  });

  const res = await app.request('http://localhost/prefixes');
  assert.strictEqual(res.status, 200);
  const cookies = res.headers.getSetCookie();
  assert.strictEqual(cookies.length, 2);

  // prefix: 'secure' produces __Secure- prefix with Secure attribute
  assert.ok(cookies[0].startsWith('__Secure-sec=val1'));
  assert.ok(cookies[0].includes('Secure'));

  // prefix: 'host' produces __Host- prefix with Secure attribute and Path=/
  assert.ok(cookies[1].startsWith('__Host-hst=val2'));
  assert.ok(cookies[1].includes('Secure'));
  assert.ok(cookies[1].includes('Path=/'));

  // __Secure- without secure throws error
  assert.throws(() => {
    const c = { header: () => {} };
    setCookie(c, '__Secure-bad', 'val', { secure: false });
  }, /__Secure- Cookie must have Secure attributes/);

  // __Host- with non-root path throws error
  assert.throws(() => {
    const c = { header: () => {} };
    setCookie(c, '__Host-bad', 'val', { secure: true, path: '/sub' });
  }, /__Host- Cookie must have Path attributes with "\/"/);
}

console.log('All hono setCookie contract tests passed.');

Seeder d'origine

anonyme