如何使用hapi.js读取浏览器中第三方API设置的已存在Cookie
Hey there! I’ve got you covered on this. Since you already know how to handle your own cookies in hapi.js, let’s focus on accessing cookies set by a third-party API in the browser.
First: The Basics of Reading Cookies in hapi.js
In hapi.js, all cookies sent with the incoming request are stored in the request.state object. To grab a specific cookie, you just reference it by name like request.state.yourCookieName.
Critical Notes on Third-Party Cookies
Before diving into code, you need to remember that browsers enforce strict rules for third-party cookies (thanks to same-origin policy and modern privacy settings). For your hapi server to read a cookie set by a third-party API, these conditions must be met:
- Domain Match: The third-party API must set the cookie’s
Domainattribute to a value that includes your server’s domain. For example, if your server isapp.example.com, the third-party should setDomain=.example.com(the leading dot makes it accessible to all subdomains underexample.com). - Path Alignment: The cookie’s
Pathshould be set to/(or a path that matches your server’s request paths) so it’s sent with all requests to your server. - SameSite & Secure: If your server and the third-party API are on different domains, the cookie must have
SameSite=NoneandSecure(sinceNonerequires HTTPS). Without these, modern browsers will block the cookie from being sent to your server. - HttpOnly: If the third-party sets
HttpOnlyon the cookie, that’s totally fine—your hapi server can still read it (this flag only blocks frontend JavaScript from accessing it).
Example Code to Read a Third-Party Cookie
Here’s a simple hapi server route that reads a third-party cookie (let’s say it’s named thirdPartySession):
const Hapi = require('@hapi/hapi'); const fs = require('fs'); const init = async () => { const server = Hapi.server({ port: 3000, host: 'app.example.com', // Make sure this matches the cookie's Domain setting // For HTTPS (required if SameSite=None is used) tls: { key: fs.readFileSync('./server.key'), cert: fs.readFileSync('./server.cert') } }); server.route({ method: 'GET', path: '/check-third-party-cookie', handler: (request, h) => { // Grab the third-party cookie from request.state const thirdPartyCookie = request.state.thirdPartySession; if (thirdPartyCookie) { return { status: 'success', message: 'Third-party cookie retrieved', cookieValue: thirdPartyCookie }; } else { return { status: 'info', message: 'No third-party cookie found. Check cookie attributes and browser settings.' }; } } }); await server.start(); console.log('Server running at %s', server.info.uri); }; process.on('unhandledRejection', err => { console.error(err); process.exit(1); }); init();
Troubleshooting If You Can’t Read the Cookie
If the cookie isn’t showing up in request.state, try these steps:
- Open your browser’s DevTools (Application tab → Cookies) and verify the third-party cookie exists and has the correct
Domain,Path,SameSite, andSecurevalues. - Check if your browser is blocking third-party cookies (many modern browsers do this by default). You may need to temporarily allow them for testing, or work with the third-party API to adjust their cookie settings to comply with current privacy standards.
- Confirm your hapi server is running on a domain that matches the cookie’s
Domainattribute (subdomains are okay if the cookie uses a wildcard domain like.example.com).
内容的提问来源于stack exchange,提问作者Gopinath Shiva

