Cookies and Forms

Reading request cookies

The server parses the Cookie header into request.cookies before routing. Read a value with get_cookie():

var session_id := request.get_cookie("session")

Setting response cookies

Use HTTPResponse.set_cookie() to add a Set-Cookie header. Options: path, max_age (seconds), domain, secure, http_only, and same_site:

response.set_cookie("sid", "abc123")                 # defaults
response.set_cookie("sid", "abc123", "/app", 3600, "example.com", true, true, "Strict")

Clear a cookie with delete_cookie():

response.delete_cookie("sid")

Token-style sessions

For state stored on the server, use SessionMiddleware (see the middleware docs). It issues an HMAC-signed cookie and loads the matching session on later requests.

Parsing urlencoded forms

request.parse_form() decodes application/x-www-form-urlencoded bodies. Repeated keys become arrays:

var form := request.parse_form()
if "name" in form:
    var name: String = form["name"]