Chrome sent duplicate cookie

Viewed 2550

I am working on a spring MVC app and found a strange issue that only happen on chrome. The logic is:

  1. user request a list of items
  2. user click on add new button and a bootstrap dialog popup allow user type in the name
  3. on submit, a post request sent to the server
  4. server create an new item and save it to db
  5. server store the new item id to cookie and send a redirect response to browser
  6. browser request item view page
  7. server pick up the item id from cookie and render the page

The above logic runs good on nearly all browsers (I didn't test on IE) except chrome. I found the root cause is chrome will store previous cookie with a different item id and at step 6 chrome send duplicate item id cookies to the server.

Any idea how to resolve this issue?

Chrome[Version 32.0.1700.41 m Aura] enter image description here

Opera[Version 20.0.1353.0] enter image description here

Firefox[Version 29.0a1 (2013-12-10)] enter image description here

Safari[Version 5.1.7 (7534.57.2)] No screen capture. But it works

2 Answers

I had something along this stored in my Chrome cookies :

1st cookie : (it was set to expire)

  • Site : dashboard.app.localhost
  • Value : access-token=123456; Domain=.app.localhost; Path=/; HttpOnly; SameSite=Strict

2nd cookie : (session cookie that shouldn't be there, I had to dig in the Chrome settings to find it)

  • Site : dashboard.app.localhost
  • Value : access-token=invalid; Domain=api.app.localhost; Path=/

Apparently the second cookie appeared due to an error on my side. However, Chrome sent it alongside the first one, creating this header :

Cookie: access-token=invalid; access-token=123456

The solution I found :

Manually delete the second cookie in the Chrome settings.

Related