CodeSampleX

Sample

jsdom 30.0.1: Synchronize document.cookie state across JSDOM windows using a shared CookieJar while enforcing origin domain, path, HttpOnly, and Secure isolation

Verified sample for npm jsdom 30.0.1: Synchronize document.cookie state across JSDOM windows using a shared CookieJar while enforcing origin domain, path…

sha256:0a7a4429b579b945c5a7aab2ad72cd42527384a514fcb0657cc0935c085d87ff

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node node npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-17
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Synchronize document.cookie state across JSDOM windows using a shared CookieJar while enforcing origin domain, path, HttpOnly, and Secure isolation
Packages
Symbols
  • CookieJar
  • JSDOM
Environment
node
Created
2026-08-17T18:53:54Z

Contract

  1. Setting document.cookie on a JSDOM window updates window.document.cookie and synchronizes the cookie into an attached CookieJar instance.
  2. Windows sharing the same CookieJar on the same origin domain read previously synchronized cookies.
  3. Windows initialized with different domains or non-matching paths on the shared CookieJar do not expose domain-scoped or path-scoped cookies.
  4. HttpOnly cookies in the CookieJar remain stored for HTTP transactions but are omitted from window.document.cookie, and client-side attempts to set HttpOnly via document.cookie are ignored.
  5. Cookies with the Secure attribute are accessible on secure HTTPS window origins but omitted when accessing an insecure HTTP window origin.
  6. Setting a cookie with max-age=0 through document.cookie removes the cookie from both window.document.cookie and the shared CookieJar.

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

csx-seed