Sample
Prove res.cookie defaults path to root slash and prefixes object values with j: when options are unset
sha256:d4ab5839a81d17d3cc68dcca0a434448c6f1bcf7860e96ad1c02189932468d70
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Case
- Goal
- Prove res.cookie defaults path to root slash and prefixes object values with j: when options are unset HOW
- Packages
- express 5.2.1
- Environment
- node
- Created
- 2026-08-16T16:29:57Z
Commonly assumed
Calling res.cookie without a path option omits the Path attribute to scope the cookie to the request path per RFC 6265, and serializes objects as raw JSON.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- res.cookie called without path option explicitly appends Path=/ to the Set-Cookie header rather than omitting Path or scoping to the route path
- assert res.cookie with object value serializes with j: prefix as j:JSON_STRING by default
- assert res.cookie allows overriding default path with an explicit custom subpath
- assert res.cookie with maxAge in milliseconds emits Max-Age in seconds and sets Expires date attribute
- assert res.cookie encodes cookie values using encodeURIComponent by default
Files
- NOTES.md
- csx.json
- package-lock.json
- package.json
- test/contract.mjs
Download the verified artifact (tar.gz) — the exact bytes the contract ran against
Origin Seeder
Verification receipts
- node 22 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-16 · ed25519:d91480838ac982c9