You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用hapi.js读取浏览器中第三方API设置的已存在Cookie

Reading Third-Party Set Cookies in hapi.js

Hey there! I’ve got you covered on this. Since you already know how to handle your own cookies in hapi.js, let’s focus on accessing cookies set by a third-party API in the browser.

First: The Basics of Reading Cookies in hapi.js

In hapi.js, all cookies sent with the incoming request are stored in the request.state object. To grab a specific cookie, you just reference it by name like request.state.yourCookieName.

Critical Notes on Third-Party Cookies

Before diving into code, you need to remember that browsers enforce strict rules for third-party cookies (thanks to same-origin policy and modern privacy settings). For your hapi server to read a cookie set by a third-party API, these conditions must be met:

  • Domain Match: The third-party API must set the cookie’s Domain attribute to a value that includes your server’s domain. For example, if your server is app.example.com, the third-party should set Domain=.example.com (the leading dot makes it accessible to all subdomains under example.com).
  • Path Alignment: The cookie’s Path should be set to / (or a path that matches your server’s request paths) so it’s sent with all requests to your server.
  • SameSite & Secure: If your server and the third-party API are on different domains, the cookie must have SameSite=None and Secure (since None requires HTTPS). Without these, modern browsers will block the cookie from being sent to your server.
  • HttpOnly: If the third-party sets HttpOnly on the cookie, that’s totally fine—your hapi server can still read it (this flag only blocks frontend JavaScript from accessing it).

Here’s a simple hapi server route that reads a third-party cookie (let’s say it’s named thirdPartySession):

const Hapi = require('@hapi/hapi');
const fs = require('fs');

const init = async () => {
    const server = Hapi.server({
        port: 3000,
        host: 'app.example.com', // Make sure this matches the cookie's Domain setting
        // For HTTPS (required if SameSite=None is used)
        tls: {
            key: fs.readFileSync('./server.key'),
            cert: fs.readFileSync('./server.cert')
        }
    });

    server.route({
        method: 'GET',
        path: '/check-third-party-cookie',
        handler: (request, h) => {
            // Grab the third-party cookie from request.state
            const thirdPartyCookie = request.state.thirdPartySession;

            if (thirdPartyCookie) {
                return {
                    status: 'success',
                    message: 'Third-party cookie retrieved',
                    cookieValue: thirdPartyCookie
                };
            } else {
                return {
                    status: 'info',
                    message: 'No third-party cookie found. Check cookie attributes and browser settings.'
                };
            }
        }
    });

    await server.start();
    console.log('Server running at %s', server.info.uri);
};

process.on('unhandledRejection', err => {
    console.error(err);
    process.exit(1);
});

init();

If the cookie isn’t showing up in request.state, try these steps:

  1. Open your browser’s DevTools (Application tab → Cookies) and verify the third-party cookie exists and has the correct Domain, Path, SameSite, and Secure values.
  2. Check if your browser is blocking third-party cookies (many modern browsers do this by default). You may need to temporarily allow them for testing, or work with the third-party API to adjust their cookie settings to comply with current privacy standards.
  3. Confirm your hapi server is running on a domain that matches the cookie’s Domain attribute (subdomains are okay if the cookie uses a wildcard domain like .example.com).

内容的提问来源于stack exchange,提问作者Gopinath Shiva

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:50:00