เครือข่าย/HTTP
Cookie Parser
แยกวิเคราะห์ส่วนหัว Set-Cookie หรือสตริง Cookie/document.cookie เป็นชื่อ ค่า แอตทริบิวต์ และตรวจสอบข้อผิดพลาดด้านความปลอดภัยทั่วไป
A Set-Cookie header or a document.cookie string looks like one solid piece of text at first glance, but it's actually made of a name, a value, and several security attributes (Secure, HttpOnly, SameSite, and more). This tool breaks the string down into its parts and flags common configuration issues.
How to use it
- Paste a Set-Cookie header from a server response, or a document.cookie string from the browser console.
- The tool lists the name, value, and every attribute (Path, Domain, Expires, Max-Age, Secure, HttpOnly, SameSite) separately.
- Common mistakes — missing Secure on an HTTPS site, SameSite=None without Secure, and so on — are flagged with a warning.
Common uses
- Debugging why a cookie isn't being set or isn't sent on later requests.
- Checking a session cookie's security configuration before shipping (is HttpOnly, Secure, SameSite actually set).
- Reading a complex document.cookie string with multiple values while debugging the frontend.
Things to keep in mind
An HttpOnly cookie is invisible to document.cookie in JavaScript — that's a deliberate XSS defense, and analyzing such a cookie needs the actual Set-Cookie header from a network request instead.
SameSite=None requires the Secure attribute — modern browsers reject such a cookie without it.
บทความเกี่ยวกับเครื่องมือนี้: คุกกี้: เหตุใดแอตทริบิวต์ Secure, HttpOnly และ SameSite จึงสำคัญ
คำถามที่พบบ่อย
แอตทริบิวต์ Secure, HttpOnly และ SameSite ควบคุมอะไรกันแน่?
Secure จำกัดคุกกี้ให้ใช้ได้เฉพาะการเชื่อมต่อ HTTPS, HttpOnly บล็อกการเข้าถึงจาก JavaScript (ช่วยป้องกันการขโมยผ่าน XSS) และ SameSite ควบคุมว่าจะส่งคุกกี้ไปพร้อมกับคำขอข้ามไซต์หรือไม่
ทำไมสตริงคุกกี้บางครั้งมีคุกกี้หลายตัวคั่นด้วยเซมิโคลอน?
เฮดเดอร์คำขอ Cookie สามารถบรรจุคู่ name=value หลายคู่จากโดเมนเดียวกันในสตริงเดียว ในขณะที่เฮดเดอร์ตอบกลับ Set-Cookie ตั้งค่าคุกกี้หนึ่งตัวต่อหนึ่งอินสแตนซ์เฮดเดอร์ แต่ละตัวมีแอตทริบิวต์ของตัวเอง
ข้อมูลคุกกี้ของฉันถูกส่งไปที่ไหนหรือไม่เมื่อวิเคราะห์ที่นี่?
ไม่ การวิเคราะห์ทำงานทั้งหมดในเบราว์เซอร์ของคุณ ไม่มีการอัปโหลดไปยังเซิร์ฟเวอร์
แอตทริบิวต์ Partitioned หมายความว่าอย่างไร?
ทำให้เว็บไซต์ที่ฝังอยู่ใน iframe มีคุกกี้ต่างกันสำหรับแต่ละเว็บไซต์หลักที่ฝังมันไว้ แทนที่จะใช้คุกกี้เดียวที่แชร์ร่วมกันทั้งหมด — เป็นส่วนหนึ่งของโครงการ CHIPS ที่ทำให้ฟังก์ชันการฝังที่ถูกต้องตามกฎหมายทำงานได้โดยไม่เปิดให้ติดตามข้ามไซต์
สามารถเก็บคุกกี้ได้กี่ตัวต่อโดเมน?
โดยทั่วไปเบราว์เซอร์จะจำกัดไว้ที่ประมาณ 50-180 คุกกี้ต่อโดเมน และประมาณ 4 KB ต่อคุกกี้ แม้ว่าขีดจำกัดที่แน่นอนจะแตกต่างกันไปตามเบราว์เซอร์