/** * This file is part of Haketilo. * * Function: Filtering request headers to remove haketilo cookies that might * have slipped through. * * Copyright (C) 2021 Wojtek Kosior * Redistribution terms are gathered in the `copyright' file. */ /* * IMPORTS_START * IMPORT extract_signed * IMPORTS_END */ function is_valid_haketilo_cookie(cookie) { const match = /^haketilo-(\w*)=(.*)$/.exec(cookie); if (!match) return false; return !extract_signed(match.slice(1, 3)).fail; } function remove_haketilo_cookies(header) { if (header.name !== "Cookie") return header; const cookies = header.value.split("; "); const value = cookies.filter(c => !is_valid_haketilo_cookie(c)).join("; "); return value ? {name: "Cookie", value} : null; } function filter_cookie_headers(headers) { return headers.map(remove_haketilo_cookies).filter(h => h); } /* * EXPORTS_START * EXPORT filter_cookie_headers * EXPORTS_END */