Sample
Synchronize document.cookie state across JSDOM windows using a shared CookieJar while enforcing origin domain, path, HttpOnly, and Secure isolation
sha256:0a7a4429b579b945c5a7aab2ad72cd42527384a514fcb0657cc0935c085d87ff
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- node
- Operating system
- linux
- Architecture
- x64
- Runtime
- node
- Language
- node
- Package manager
- npm
Verification-run environments
- Execution context
- node 22
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- node 22
- Language
- javascript
- Package manager
- npm
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17
Case
- Goal
- Synchronize document.cookie state across JSDOM windows using a shared CookieJar while enforcing origin domain, path, HttpOnly, and Secure isolation HOW
- Packages
-
jsdom 30.0.1
- Environment
- node
- Created
- 2026-08-17T18:53:54Z
Contract
- Setting document.cookie on a JSDOM window updates window.document.cookie and synchronizes the cookie into an attached CookieJar instance.
- Windows sharing the same CookieJar on the same origin domain read previously synchronized cookies.
- Windows initialized with different domains or non-matching paths on the shared CookieJar do not expose domain-scoped or path-scoped cookies.
- HttpOnly cookies in the CookieJar remain stored for HTTP transactions but are omitted from window.document.cookie, and client-side attempts to set HttpOnly via document.cookie are ignored.
- Cookies with the Secure attribute are accessible on secure HTTPS window origins but omitted when accessing an insecure HTTP window origin.
- Setting a cookie with max-age=0 through document.cookie removes the cookie from both window.document.cookie and the shared CookieJar.
Files
- NOTES.md
- csx.json
- package-lock.json
- package.json
- test/contract.mjs
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- node 22 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17 · ed25519:d91480838ac982c9