Mạng/HTTP
Cookie Parser
Phân tách header Set-Cookie hoặc chuỗi Cookie/document.cookie thành tên, giá trị, thuộc tính và kiểm tra các lỗi bảo mật thường gặp.
A Set-Cookie header or a document.cookie string looks like one solid piece of text at first glance, but it's actually made of a name, a value, and several security attributes (Secure, HttpOnly, SameSite, and more). This tool breaks the string down into its parts and flags common configuration issues.
How to use it
- Paste a Set-Cookie header from a server response, or a document.cookie string from the browser console.
- The tool lists the name, value, and every attribute (Path, Domain, Expires, Max-Age, Secure, HttpOnly, SameSite) separately.
- Common mistakes — missing Secure on an HTTPS site, SameSite=None without Secure, and so on — are flagged with a warning.
Common uses
- Debugging why a cookie isn't being set or isn't sent on later requests.
- Checking a session cookie's security configuration before shipping (is HttpOnly, Secure, SameSite actually set).
- Reading a complex document.cookie string with multiple values while debugging the frontend.
Things to keep in mind
An HttpOnly cookie is invisible to document.cookie in JavaScript — that's a deliberate XSS defense, and analyzing such a cookie needs the actual Set-Cookie header from a network request instead.
SameSite=None requires the Secure attribute — modern browsers reject such a cookie without it.
Bài viết về công cụ này: Cookie: một đoạn văn bản nhỏ lưu giữ trạng thái phiên làm việc như thế nào
Câu hỏi thường gặp
Các thuộc tính Secure, HttpOnly và SameSite thực sự kiểm soát điều gì?
Secure giới hạn cookie chỉ với kết nối HTTPS, HttpOnly chặn truy cập từ JavaScript (giúp ngăn đánh cắp qua XSS), và SameSite kiểm soát việc cookie có được gửi kèm yêu cầu xuyên site hay không.
Vì sao một chuỗi cookie đôi khi chứa nhiều cookie phân tách bằng dấu chấm phẩy?
Header yêu cầu Cookie có thể mang nhiều cặp tên=giá trị từ cùng một domain trong một chuỗi, còn header phản hồi Set-Cookie đặt một cookie cho mỗi lần xuất hiện header, mỗi cái có thuộc tính riêng.
Dữ liệu cookie của tôi có được gửi đi đâu khi phân tích ở đây không?
Không. Việc phân tích diễn ra hoàn toàn trong trình duyệt của bạn — không có gì được tải lên máy chủ.
Thuộc tính Partitioned có nghĩa là gì?
Nó cho phép một trang web được nhúng trong iframe có cookie khác nhau cho từng trang cha lưu trữ nó, thay vì một cookie duy nhất được chia sẻ giữa tất cả — một phần của sáng kiến CHIPS giúp các chức năng nhúng hợp pháp hoạt động mà không cho phép theo dõi liên trang.
Có thể lưu trữ bao nhiêu cookie cho mỗi domain?
Trình duyệt thường giới hạn khoảng 50-180 cookie mỗi domain và khoảng 4 KB mỗi cookie, dù giới hạn chính xác khác nhau tùy trình duyệt.