Cookies and Forms
Reading request cookies
The server parses the Cookie header into request.cookies before routing. Read a value with get_cookie():
var session_id := request.get_cookie("session")
Setting response cookies
Use HTTPResponse.set_cookie() to add a Set-Cookie header. Options: path, max_age (seconds), domain, secure, http_only, and same_site:
response.set_cookie("sid", "abc123") # defaults
response.set_cookie("sid", "abc123", "/app", 3600, "example.com", true, true, "Strict")
Clear a cookie with delete_cookie():
response.delete_cookie("sid")
Token-style sessions
For state stored on the server, use SessionMiddleware (see the middleware docs). It issues an HMAC-signed cookie and loads the matching session on later requests.
Parsing urlencoded forms
request.parse_form() decodes application/x-www-form-urlencoded bodies. Repeated keys become arrays:
var form := request.parse_form()
if "name" in form:
var name: String = form["name"]