-
Added support for the draft
Partitionedattribute.The new
CookieBuilder::partition(),Cookie::partitioned(), andCookie::set_partitioned()methods allow enabling and/or disabling the attribute. Additionally, the attribute is recognized during parsing. -
Added
CookieBuilder::removal(), counterpart toCookie::make_removal().
-
The MSRV is now 1.56.
-
Cookie::value()no longer trims surrounding double quotes. (89eddd)Use
Cookie::value_trimmed()for the previous behavior. -
Many methods now expect a
T: Into<Cookie>in place ofCookie. (49ff7b)Functions and methods that previously accepted a
Cookienow accept anyT: Into<Cookie>. This particularly affects theCookieJarAPI, which now allows simpler addition and removal of cookies:jar.add(("foo", "bar"));jar.add(Cookie::build(("foo", "bar")).path("/"));jar.remove("foo");jar.remove(Cookie::build("foo").path("/"));
-
CookieJar::force_remove()now expects aT: AsRef<str>in place of&Cookie.Force-removal never requires more information than a cookie's name. The API has been simplified to reflect this.
-
CookieBuilder::finish()was deprecated in favor ofCookieBuilder::build().This largely serves as a compile-time notice that calling
finish()orbuild()is largely unnecessary given thatCookieBuilderimplementsInto<Cookie>. -
Cookie::named()was deprecated in favor of usingCookie::build()orCookie::from().Cookie::named("foo")is equivalent toCookie::from("foo").Cookie::build("foo")begins building a cookie equivalent toCookie::named("foo").
-
Added
Cookie::value_trimmed()andCookie::name_value_trimmed().These versions of
Cookie::value()andCookie::name_value(), respectively, trim a matching pair of surrounding double quotes from the cookie's value, if any are present. -
String-like types, tuples of string-like types, and
CookieBuilderimplementInto<Cookie>.Implementations of
Into<Cookie>for string-like types (&str,String,Cow<str>), tuples of string-like types(name: string, value: string), andCookieBuilderwere added. The former implementations create a cookie with a name corresponding to the string and an empty value. The tuple implementation creates a cookie with the given name and value strings. TheCookieBuilderimplementation returns the built cookie. -
KeyimplementsDebug.To not leak sensitive information, the representation is simply
"Key". -
CookieBuilderimplementsBorrow{Mut}<Cookie>,As{Ref,Mut}<Cookie>,Display. -
Added
CookieBuilder::inner{_mut}()to (mutably) borrow cookies being built. -
Added
PrefixedJarandCookieJar::prefixed{_mut}(), which implement the cookie prefixes HTTP draft.
See the entry above for 0.18.0.
-
Cookie parsing no longer removes a
.Domainprefix.Cookie::domain()now removes a.prefix before returning.As these changes are inverses, they are not likely observable. The change only affects manually set
domainvalues via the.domain()builder method, theset_domain()setter method, or similar, which will now have a prefix of.removed when returned byCookie::domain(). This results in more consistent treatment ofDomainvalues.
-
Added
Cookie::split_parse()andCookie::split_parse_encoded()methods.The methods split a
;-joined cookie string and parse/decode the split values. They return a newly introduced iterator value of typeSplitCookiesover the parse results.
- Parsing fuzzers were introduced and run for 48 CPU hours without failure.
base64was updated to0.21.
base64was updated to0.20.
- The
,,(, and)are percent-encoded/decoded when encoding is used. - The
aes-gcmdependency was updated to 0.10.
- The MSRV is now
1.53, up from1.41in0.15. timehas been updated to0.3and is reexported from the crate root.
rust-cryptodependencies were updated to their latest versions.
- A panic that could result from non-char boundary indexing was fixed.
- Stale doc references to version
0.14were updated.
Cookie::force_remove()takes&Cookieinstead ofCookie.- Child jar methods split into immutable and mutable versions
(
Cookie::{private{_mut}, signed{_mut}}). Cookie::encoded()returns a newDisplaystruct.- Dates with year
<= 99are handled like Chrome: range0..=68maps to2000..=2068,69..=99to1969..=1999. Cookie::{set_}expires()operates on a newExpirationenum.
- Added
Cookie::make_removal()to manually create expired cookies. - Added
Cookie::stripped()display variant to print only thenameandvalueof a cookie. Keyimplements a constant-timePartialEq.- Added
Key::master()to retrieve the full 512-bit master key. - Added
PrivateJar::decrypt()to manually decrypt an encryptedCookie. - Added
SignedJar::verify()to manually verify a signedCookie. Cookie::expires()returns anOption<Expiration>to allow distinguishing between unset andNoneexpirations.- Added
Cookie::expires_datetime()to retrieve the expiration as anOffsetDateTime. - Added
Cookie::unset_expires()to unset expirations.
- MSRV is 1.41.
rust-cryptodependencies were updated to their latest versions.
- Documentation now builds on the stable channel.
rust-cryptodependencies were updated to their latest versions.- Fixed 'interator' -> 'iterator' documentation typo.
- Updated
base64dependency to 0.12. - Updated minimum
timedependency to correct version: 0.2.11. - Added
readmekey toCargo.toml, updatedlicensefield.
- The
Key::from_master()method was deprecated in favor of the more aptly namedKey::derive_from(). - The deprecated
CookieJar::clear()method was removed.
- Added
Key::from()to create aKeystructure from a full-length key. - Signed and private cookie jars can be individually enabled via the new
signedandprivatefeatures, respectively. - Key derivation via key expansion can be individually enabled via the new
key-expansionfeature.
ringis no longer a dependency:RustCrypto-based cryptography is used in lieu ofring. Prior to their inclusion here, thehmacandhkdfcrates were audited.- Quotes, if present, are stripped from cookie values when parsing.
- The
timedependency was unpinned from0.2.4, allowing any0.2.xversion oftimewherex >= 6.
- The
timedependency was pinned to0.2.4due to upstream breaking changes in0.2.5.
- Added the
CookieJar::reset_delta()method, which reverts all delta changes to aCookieJar.
timewas updated from 0.1 to 0.2.ringwas updated from 0.14 to 0.16.SameSite::Nonenow writesSameSite=Noneto correspond with updatedSameSitedraft.SameSitecan be unset by passingNonetoCookie::set_same_site().CookieBuildergained a lifetime:CookieBuilder<'c>.
- Added a CHANGELOG.
expires,max_age,path, anddomaincan be unset by passingNoneto the respectiveCookie::set_{field}()method.- The "Expires" field is limited to a date-time of Dec 31, 9999, 23:59:59.
- The
%character is now properly encoded and decoded. - Constructor methods on
CookieBuilderallow non-static lifetimes.