From: noreply@... Date: 2005-10-07T06:17:09+09:00 Subject: [ ruby-Patches-2595 ] Cookies from Nokia devices may not be parsed correctly Patches item #2595, was opened at 2005-10-06 23:08 You can respond by visiting: http://rubyforge.org/tracker/?func=detail&atid=1700&aid=2595&group_id=426 Category: Ruby1.8 Group: None Status: Open Resolution: None Priority: 3 Submitted By: August Z. Flatby (augustzf) Assigned to: Nobody (None) Summary: Cookies from Nokia devices may not be parsed correctly Initial Comment: Nokia 6630 with firmware V 2.39.15 sends cookies in the following format: (key=val;)* That is, the value always has a trailing semicolon, and there is no space between successive cookie key/value pairs. In Ruby 1.8.2 and 1.8.3 CGI::Cookie.parse assumes that cookies are always separated by a semicolon followed by a space. This behaviour causes cookies from the Nokia device to be incorrectly parsed. For example, if you set a cookie named "foo" to value "bar" it will be returned with value "bar;" from CGI::Cookie::parse. This can cause session IDs not to be recognized. Further, if more than one cookie is sent, for example "foo=bar;snook=true;" then it will be parsed as one cookie with key "foo" and value "bar;snook=true;". The following patch (for 1.8.3) fixes this problem. --- cgi.bak 2005-10-06 22:21:54.000000000 +0200 +++ cgi.rb 2005-10-06 22:20:27.000000000 +0200 @@ -870,7 +870,7 @@ cookies = Hash.new([]) return cookies unless raw_cookie - raw_cookie.split(/[;,] /).each do |pairs| + raw_cookie.split(/[;,]\s?/).each do |pairs| name, values = pairs.split('=',2) next unless name and values name = CGI::unescape(name) August Z. Flatby ---------------------------------------------------------------------- You can respond by visiting: http://rubyforge.org/tracker/?func=detail&atid=1700&aid=2595&group_id=426