diff --git a/client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java b/client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java index 31c22ae84..b4d90c0ea 100644 --- a/client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java +++ b/client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java @@ -147,13 +147,15 @@ private static String requestPath(Uri requestUri) { private static AbstractMap.SimpleEntry cookieDomain(@Nullable String cookieDomain, String requestDomain) { if (cookieDomain != null) { String normalizedCookieDomain = cookieDomain.toLowerCase(); - return new AbstractMap.SimpleEntry<>( - !cookieDomain.isEmpty() && cookieDomain.charAt(0) == '.' ? - normalizedCookieDomain.substring(1) : - normalizedCookieDomain, false); - } else { - return new AbstractMap.SimpleEntry<>(requestDomain, true); + String domain = !cookieDomain.isEmpty() && cookieDomain.charAt(0) == '.' ? + normalizedCookieDomain.substring(1) : + normalizedCookieDomain; + // Domain=. leaves nothing, and an empty domain makes the cookie host-only (RFC 6265 section 5.3 step 6). + if (!domain.isEmpty()) { + return new AbstractMap.SimpleEntry<>(domain, false); + } } + return new AbstractMap.SimpleEntry<>(requestDomain, true); } // rfc6265#section-5.2.4 diff --git a/client/src/test/java/org/asynchttpclient/cookie/ThreadSafeCookieStoreGetTest.java b/client/src/test/java/org/asynchttpclient/cookie/ThreadSafeCookieStoreGetTest.java index a8db3fd88..251aabeb7 100644 --- a/client/src/test/java/org/asynchttpclient/cookie/ThreadSafeCookieStoreGetTest.java +++ b/client/src/test/java/org/asynchttpclient/cookie/ThreadSafeCookieStoreGetTest.java @@ -51,6 +51,15 @@ private static Set setOf(String... values) { return out; } + @Test + public void aDomainOfJustADotMakesTheCookieHostOnly() { + ThreadSafeCookieStore store = new ThreadSafeCookieStore(); + store.add(Uri.create("http://www.foo.com/"), ClientCookieDecoder.LAX.decode("ALPHA=VALUE1; Domain=.; Path=/")); + + assertEquals(setOf("ALPHA=VALUE1"), namesValues(store.get(Uri.create("http://www.foo.com/")))); + assertTrue(store.get(Uri.create("http://sub.www.foo.com/")).isEmpty(), "host-only, so not for subdomains"); + } + @Test public void returnsCookieOnExactDomainAndPath() { ThreadSafeCookieStore store = new ThreadSafeCookieStore();