# Handling cookies in HTTP parser

**URL:** <https://discuss.elastic.co/t/handling-cookies-in-http-parser/67335>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [November 28, 2016, 11:16am UTC](https://discuss.elastic.co/t/handling-cookies-in-http-parser/67335 "2016-11-28T11:16:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PinXo](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@PinXo](https://discuss.elastic.co/u/PinXo)\
**Post date:** [November 28, 2016, 11:16am UTC](https://discuss.elastic.co/t/handling-cookies-in-http-parser/67335/1 "2016-11-28T11:16:03Z")

</div>

There are several errors parsing Cookies in HTTP protocol.

1. If split\_cookies is enabled, all the other request headers are lost.
2. If a response has two or more cookies, the json is not correctly composed.

This could be an example with 5 cookies:

```
HTTP/1.0 200 OK
Date: Mon, 28 Nov 2016 08:49:56 GMT
Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6
X-Powered-By: PHP/4.4.4-8+etch6
Set-Cookie: name1=justname
Set-Cookie: name2=withexpire; expires=Wed, 28 Dec 2016 08:49:57 GMT
Set-Cookie: name3=withexpirepath; expires=Wed, 28 Dec 2016 08:49:57 GMT; path=/test/index.php
Set-Cookie: name4=withexpirepathdomain; expires=Wed, 28 Dec 2016 08:49:57 GMT; path=/test/index.php; domain=ZZZZZ
Set-Cookie: name5=withexpiredomainsecure; expires=Wed, 28 Dec 2016 08:49:57 GMT; path=/test; domain=ZZZZZ; secure
Content-Type: text/html; charset=iso-8859-1
X-Cache: MISS from XXXXX
X-Cache-Lookup: MISS from XXXX:YYYY
Via: 1.0 XXXX (squid)
Connection: close

```

With this response, cookies are overwritten (Notice that cookie's name is name5 not naname5 and the other 4 cookies are missing):

```
"response" : {
			"code" : 200,
			"headers" : {
				"connection" : "Keep-Alive",
				"content-length" : 21,
				"content-type" : "text/html; charset=iso-8859-1",
				"date" : "Mon, 28 Nov 2016 09:17:32 GMT",
				"keep-alive" : "timeout=15, max=100",
				"server" : "Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6",
				"set-cookie" : "naname5=withexpiredomainsecure; expires=Wed, 28 Dec 2016 09:17:32 GMT; path=/test; domain=ZZZZZ; secure\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000, \u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000, \u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000",
				"transfer-encoding" : "chunked",
				"x-powered-by" : "PHP/4.4.4-8+etch6"
			},
			"phrase" : "OK"
		}

```

This is corrected adding a "+" in http\_parser.go  
`off = copy(composed[off:], []byte(", "))`  
would be  
`off += copy(composed[off:], []byte(", "))`

With that change we obtain:

```
"headers" : {
				"connection" : "Keep-Alive",
				"content-length" : 21,
				"content-type" : "text/html; charset=iso-8859-1",
				"date" : "Mon, 28 Nov 2016 09:24:03 GMT",
				"keep-alive" : "timeout=15, max=100",
				"server" : "Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6",
				"set-cookie" : "name1=justname, name2=withexpire; expires=Wed, 28 Dec 2016 09:24:03 GMT, name3=withexpirepath; expires=Wed, 28 Dec 2016 09:24:03 GMT; path=/test/index.php, name4=withexpirepathdomain; expires=Wed, 28 Dec 2016 09:24:03 GMT; path=/test/index.php; domain=ZZZZZ, name5=withexpirepathdomainsecure; expires=Wed, 28 Dec 2016 09:24:03 GMT; path=/test; domain=ZZZZZ; secure",
				"transfer-encoding" : "chunked",
				"x-powered-by" : "PHP/4.4.4-8+etch6"
			},
```

---

<div class="post-metadata">

**Author:** ![PinXo](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@PinXo](https://discuss.elastic.co/u/PinXo)\
**Post date:** [November 28, 2016, 11:17am UTC](https://discuss.elastic.co/t/handling-cookies-in-http-parser/67335/2 "2016-11-28T11:17:02Z")

</div>

After that last change, enabling split\_cookies option this is the result:

```
"headers" : {
				"connection" : "Keep-Alive",
				"content-length" : 21,
				"content-type" : "text/html; charset=iso-8859-1",
				"date" : "Mon, 28 Nov 2016 09:53:50 GMT",
				"keep-alive" : "timeout=15, max=100",
				"server" : "Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6",
				"set-cookie" : {
					"domain" : "ZZZZZ",
					"expires" : "Wed, 28 Dec 2016 09:53:50 GMT",
					"name1" : "justname, name2=withexpire",
					"path" : "/test"
				},
				"transfer-encoding" : "chunked",
				"x-powered-by" : "PHP/4.4.4-8+etch6"
			},

```

The composed field separator is a comma but in split\_cookies function, it is used a semicolon.  
In other words, field "cookie" is composed with semicolon separator and "set-cookie" with comma, but split\_cookies work with semicolons.  
If we set semicolon also for set-cookie field, the cookie's inner fields break the split, so it seems the splitcookie function should be different for cookie and set-cookie.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 29, 2016, 8:15pm UTC](https://discuss.elastic.co/t/handling-cookies-in-http-parser/67335/3 "2016-11-29T20:15:49Z")

</div>

Related PR: [https://github.com/elastic/beats/pull/3065](https://github.com/elastic/beats/pull/3065)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2016, 8:15pm UTC](https://discuss.elastic.co/t/handling-cookies-in-http-parser/67335/4 "2016-12-27T20:15:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
