示例
hono 4.13.7: setCookie
已验证示例 — npm hono 4.13.7: setCookie. contract 在 node 22 · linux debian/x64 · docker 上运行并通过: hono exports setCookie from hono/cookie entrypoint and version is…
sha256:f80d60d374e8454d1649d8f0e5da3cbbb4ba3c03bc558d16295cb43cb99d0acf
本网络只提供一件事:能构建的样本。它在沙箱中运行并保留签名回执。它不评级、不担保——同样的代码能否在你的环境构建,它没有测量过。
提交了通过的契约回执的不同签名密钥数量。为 1 表示只有作者;大于 1 表示还有其他人构建过。密钥是自行生成的,背后没有注册身份,因此计的是密钥而非人。
MIT-0
执行证据
声明的环境与签名的运行分开呈现,你可以看到这个样本究竟运行了什么、在哪里运行。
- 证据依据
- 签名契约通过
- 验证回执
- 1
- 构建过它的签名密钥
- 1
声明的环境
node 22.23 linux 24 · ubuntu · glibc 2.39 x64 node 22.23 javascript npm 10
验证运行环境
| 环境 | 契约 | 阶段 | 运行日期 |
|---|---|---|---|
| node 22 · linux debian/x64 · docker ed25519:c1973797be207ac4 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · node-typescript@1node:22@sha256:8a34c4ab3ea2… |
2026-09-06 |
案例
HOW- 目标
- verify setCookie in pkg:npm/hono@4.13.7
- 符号
-
- setCookie
- 环境
- node 22.23.2
- 创建时间
- 2026-09-06T04:18:54Z
契约
- hono exports setCookie from hono/cookie entrypoint and version is 4.13.7
- setCookie sets Set-Cookie response header with name and URI-encoded value
- setCookie configures path, domain, secure, httpOnly, maxAge, sameSite, and expires attributes
- setCookie appends multiple cookies to the Set-Cookie response header without overwriting
- setCookie supports secure and host prefixes and enforces security attributes
文件
- PROMPT.md
- csx.json
- package-lock.json
- package.json
- spec.json
- test/contract.mjs
源代码
Clean-room public code sample — generation instructions
Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.
A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.
Goal: verify setCookie in pkg:npm/hono@4.13.7
Kind: HOW
Use EXACTLY these public packages and versions:
- pkg:npm/hono@4.13.7
Demonstrate these symbols/APIs:
- setCookie
Rules:
- One focused purpose; the smallest project that proves the goal.
- Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
- Pin every dependency with a lockfile so resolution is reproducible.
- No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
- No personal names, emails, company names, or project identifiers of any kind.
- No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
- Keep it under 200 files and 256KB packed.
{"case":{"caseId":"case:sha256:2012f3c4350ff31b63ec2542e5edf1bc2f7998645cad6a57483ce5100cd1c222","contract":["hono exports setCookie from hono/cookie entrypoint and version is 4.13.7","setCookie sets Set-Cookie response header with name and URI-encoded value","setCookie configures path, domain, secure, httpOnly, maxAge, sameSite, and expires attributes","setCookie appends multiple cookies to the Set-Cookie response header without overwriting","setCookie supports secure and host prefixes and enforces security attributes"],"goal":"verify setCookie in pkg:npm/hono@4.13.7","kind":"HOW","packages":["pkg:npm/hono@4.13.7"],"schemaVersion":1,"symbols":["setCookie"]},"contractCommand":["node","test/contract.mjs"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"npm","executionContext":"node","language":"javascript","libc":"glibc","libcVersion":"2.39","moduleSystem":"esm","os":"linux","osVersionBucket":"24","packageManager":"npm","packageManagerVersion":"10.9.8","runtime":"node","runtimeVersion":"22.23.2","schemaVersion":1},"license":"MIT-0","packages":["pkg:npm/hono@4.13.7"],"schemaVersion":1,"subject":"pkg:npm/hono@4.13.7","symbols":["setCookie"],"verifierAdapter":"node-typescript@1"}
{
"name": "sample-hono-setcookie",
"version": "1.0.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "sample-hono-setcookie",
"version": "1.0.0",
"license": "MIT-0",
"dependencies": {
"hono": "4.13.7"
}
},
"node_modules/hono": {
"version": "4.13.7",
"resolved": "https://registry.npmjs.org/hono/-/hono-4.13.7.tgz",
"integrity": "sha512-c8/gF9ac8Y78/agExVocyLevgR+JlpNB444Py0FSX8pJoPdYUfUzRcXtYEYGwt6l19qIlVZPN5Mfsw9jFShmQQ==",
"license": "MIT",
"engines": {
"node": ">=16.9.0"
}
}
}
}
{
"name": "sample-hono-setcookie",
"version": "1.0.0",
"type": "module",
"private": true,
"license": "MIT-0",
"dependencies": {
"hono": "4.13.7"
}
}
{
"schemaVersion": 1,
"goal": "verify setCookie in pkg:npm/hono@4.13.7",
"kind": "HOW",
"packages": [
"pkg:npm/hono@4.13.7"
],
"symbols": [
"setCookie"
]
}
import assert from 'node:assert/strict';
import fs from 'node:fs';
import { fileURLToPath } from 'node:url';
import { Hono } from 'hono';
import { setCookie } from 'hono/cookie';
// Contract 1: hono exports setCookie from hono/cookie entrypoint and version is 4.13.7
{
const honoEntryUrl = import.meta.resolve('hono');
const pkgJsonPath = fileURLToPath(new URL('../package.json', honoEntryUrl));
assert.ok(fs.existsSync(pkgJsonPath));
const pkgJson = JSON.parse(fs.readFileSync(pkgJsonPath, 'utf8'));
assert.strictEqual(pkgJson.name, 'hono');
assert.strictEqual(pkgJson.version, '4.13.7');
assert.ok(pkgJson.exports['./cookie']);
assert.strictEqual(typeof setCookie, 'function');
}
// Contract 2: setCookie sets Set-Cookie response header with name and URI-encoded value
{
const app = new Hono();
app.get('/basic', (c) => {
setCookie(c, 'theme', 'dark');
setCookie(c, 'message', 'hello world');
return c.text('ok');
});
const res = await app.request('http://localhost/basic');
assert.strictEqual(res.status, 200);
const cookies = res.headers.getSetCookie();
assert.strictEqual(cookies.length, 2);
assert.ok(cookies[0].startsWith('theme=dark; Path=/'));
assert.ok(cookies[1].startsWith('message=hello%20world; Path=/'));
}
// Contract 3: setCookie configures path, domain, secure, httpOnly, maxAge, sameSite, and expires attributes
{
const app = new Hono();
const expiresDate = new Date(Date.now() + 86400 * 1000);
app.get('/options', (c) => {
setCookie(c, 'session', 'sess123', {
path: '/api',
domain: 'example.com',
secure: true,
httpOnly: true,
maxAge: 3600,
sameSite: 'Strict',
expires: expiresDate,
});
return c.text('options set');
});
const res = await app.request('http://localhost/options');
assert.strictEqual(res.status, 200);
const cookieHeader = res.headers.get('set-cookie');
assert.ok(cookieHeader);
assert.ok(cookieHeader.includes('session=sess123'));
assert.ok(cookieHeader.includes('Path=/api'));
assert.ok(cookieHeader.includes('Domain=example.com'));
assert.ok(cookieHeader.includes('Secure'));
assert.ok(cookieHeader.includes('HttpOnly'));
assert.ok(cookieHeader.includes('Max-Age=3600'));
assert.ok(cookieHeader.includes('SameSite=Strict'));
assert.ok(cookieHeader.includes(`Expires=${expiresDate.toUTCString()}`));
}
// Contract 4: setCookie appends multiple cookies to the Set-Cookie response header without overwriting
{
const app = new Hono();
app.get('/multiple', (c) => {
setCookie(c, 'c1', 'v1');
setCookie(c, 'c2', 'v2');
setCookie(c, 'c3', 'v3');
return c.text('done');
});
const res = await app.request('http://localhost/multiple');
assert.strictEqual(res.status, 200);
const cookies = res.headers.getSetCookie();
assert.strictEqual(cookies.length, 3);
assert.ok(cookies.some((c) => c.startsWith('c1=v1')));
assert.ok(cookies.some((c) => c.startsWith('c2=v2')));
assert.ok(cookies.some((c) => c.startsWith('c3=v3')));
}
// Contract 5: setCookie supports secure and host prefixes and enforces security attributes
{
const app = new Hono();
app.get('/prefixes', (c) => {
setCookie(c, 'sec', 'val1', { prefix: 'secure' });
setCookie(c, 'hst', 'val2', { prefix: 'host' });
return c.text('prefixed');
});
const res = await app.request('http://localhost/prefixes');
assert.strictEqual(res.status, 200);
const cookies = res.headers.getSetCookie();
assert.strictEqual(cookies.length, 2);
// prefix: 'secure' produces __Secure- prefix with Secure attribute
assert.ok(cookies[0].startsWith('__Secure-sec=val1'));
assert.ok(cookies[0].includes('Secure'));
// prefix: 'host' produces __Host- prefix with Secure attribute and Path=/
assert.ok(cookies[1].startsWith('__Host-hst=val2'));
assert.ok(cookies[1].includes('Secure'));
assert.ok(cookies[1].includes('Path=/'));
// __Secure- without secure throws error
assert.throws(() => {
const c = { header: () => {} };
setCookie(c, '__Secure-bad', 'val', { secure: false });
}, /__Secure- Cookie must have Secure attributes/);
// __Host- with non-root path throws error
assert.throws(() => {
const c = { header: () => {} };
setCookie(c, '__Host-bad', 'val', { secure: true, path: '/sub' });
}, /__Host- Cookie must have Path attributes with "\/"/);
}
console.log('All hono setCookie contract tests passed.');
原始种子者
匿名