HTTP cookies: Difference between revisions
wikademia>Eme No edit summary |
No edit summary |
||
| Line 1: | Line 1: | ||
{{ | '''HTTP cookies''' are small pieces of data that a website can ask a web browser to store and later send back to the website. Cookies are an important part of how the modern [[World Wide Web]] works because the underlying [[HTTP]] protocol is largely stateless. Without some method of maintaining state, a website would otherwise have difficulty remembering that two separate requests came from the same browser or session. | ||
Cookies can be used for useful functions such as keeping a person logged into a website, remembering preferences, maintaining a shopping cart, improving security, measuring website usage, and personalizing a website. Cookies can also be used for advertising and tracking, which has made them an important subject in discussions of [[privacy]], [[computer security]], and Internet regulation. | |||
Learning about cookies can help people better understand what happens between a browser and a web server, how authentication works, and how websites can remember information between page requests. | |||
== How cookies work == | |||
A web server can send a cookie to a browser using the HTTP <code>Set-Cookie</code> response header. | |||
A simplified example might look like: | |||
<pre> | |||
Set-Cookie: session=abc123 | |||
</pre> | |||
The browser can store the cookie and return it to the appropriate website in later requests using the <code>Cookie</code> request header. | |||
For example: | |||
<pre> | |||
Cookie: session=abc123 | |||
</pre> | |||
The server can then associate <code>abc123</code> with information stored on the server, such as a logged-in account or an active session. | |||
The cookie itself does not necessarily contain all of the information about the user. A cookie may simply contain an identifier that corresponds with information maintained in a database on the server. | |||
== Common uses of cookies == | |||
Cookies have many possible uses. | |||
{{Col}} | |||
* User authentication | |||
* Login sessions | |||
* Shopping carts | |||
* Website preferences | |||
* Language preferences | |||
* Theme preferences | |||
* Security functions | |||
{{break}} | |||
* Analytics | |||
* Advertising | |||
* Personalization | |||
* A/B testing | |||
* Remembering previous activity | |||
* Session management | |||
* Fraud and abuse prevention | |||
{{colend}} | |||
A MediaWiki installation, for example, may use cookies to maintain login sessions and remember certain user preferences. | |||
It is therefore inaccurate to describe cookies simply as tracking mechanisms. Tracking is one possible use of cookies, but many websites would lose important functionality if all cookies were removed. | |||
== Session and persistent cookies == | |||
Cookies can have different lifetimes. | |||
A '''session cookie''' is generally intended to exist for the duration of a browser session. If a cookie does not specify an expiration time or maximum age, browsers normally treat it as a session cookie. | |||
A '''persistent cookie''' contains an expiration time or maximum lifetime. It can remain stored after the browser is closed and may be available during a later visit. | |||
Persistent cookies can be useful for features such as remembering login status or preferences. | |||
They can also allow information about activity to remain associated with a browser for longer periods. | |||
== Cookie attributes == | |||
Cookies can include attributes that determine how and when they are used. | |||
Important attributes include: | |||
* <code>Expires</code> or <code>Max-Age</code>, which can determine how long a cookie remains valid. | |||
* <code>Domain</code>, which controls the domain scope of a cookie. | |||
* <code>Path</code>, which limits the request paths for which a cookie is sent. | |||
* <code>Secure</code>, which instructs the browser to send the cookie only through secure HTTPS connections, subject to browser rules. | |||
* <code>HttpOnly</code>, which prevents ordinary JavaScript access to the cookie and can help protect sensitive cookies from some attacks. | |||
* <code>SameSite</code>, which controls when cookies are sent in requests involving different sites. | |||
The <code>SameSite</code> attribute can generally use values such as <code>Strict</code>, <code>Lax</code>, or <code>None</code>. Cookies using <code>SameSite=None</code> must also use <code>Secure</code> in modern browsers. | |||
Many modern browsers apply a Lax or Lax-like behavior when <code>SameSite</code> is not explicitly specified. | |||
== First-party and third-party cookies == | |||
A distinction is often made between '''first-party cookies''' and '''third-party cookies'''. | |||
A first-party cookie is associated with the site that a person is directly visiting. | |||
A third-party cookie generally involves content or services provided by another site within the page being visited. | |||
For example, a website might contain advertising, analytics, embedded video, or other resources provided by another company. Depending on the browser, technology, and privacy settings involved, those services may attempt to use cookies or other forms of storage. | |||
Third-party cookies have historically been widely used for advertising and cross-site tracking. Browsers increasingly restrict third-party cookie behavior, and website developers should not assume that third-party cookies will always be available. | |||
== Cookies, privacy, and tracking == | |||
Cookies can create privacy concerns when they are used to build records of a person's activity across websites or over long periods of time. | |||
However, deleting or blocking cookies does not necessarily prevent all forms of tracking. | |||
Websites and third-party services may also use: | |||
{{Col}} | |||
* IP addresses | |||
* Browser storage | |||
* Account identifiers | |||
* Device information | |||
* Tracking parameters in URLs | |||
{{break}} | |||
* Browser characteristics | |||
* Server logs | |||
* Advertising identifiers | |||
* Embedded resources | |||
* Other technical identifiers | |||
{{colend}} | |||
Privacy therefore involves more than managing cookies alone. | |||
Users can generally inspect, block, or delete cookies through their browser. Browsers may also provide settings for preventing cross-site tracking or automatically deleting site data. | |||
== Cookies and computer security == | |||
Poor cookie configuration can create security problems. | |||
Authentication cookies are particularly important because possession of a valid session cookie may allow a server to treat a browser as an authenticated user. | |||
Developers can reduce some risks by using HTTPS, appropriate <code>Secure</code> and <code>HttpOnly</code> attributes, appropriate <code>SameSite</code> settings, limited cookie lifetimes, secure session management, and other [[computer security]] practices. | |||
Cookies can also be relevant to attacks such as [[cross-site scripting]], [[cross-site request forgery]], and session fixation. | |||
Cookie security should therefore be considered as part of a larger web application security strategy rather than as an isolated technical issue. | |||
== Learning activities == | |||
HTTP cookies are relatively easy to study directly using a modern web browser. | |||
Possible activities include: | |||
# Open the browser developer tools and examine the cookies stored by several websites. | |||
# Compare session cookies with persistent cookies. | |||
# Examine the <code>Secure</code>, <code>HttpOnly</code>, and <code>SameSite</code> attributes of different cookies. | |||
# Delete a website's cookies and observe which features change. | |||
# Log into a test website and observe when authentication cookies are created and removed. | |||
# Use a local web server to experiment with different <code>Set-Cookie</code> headers. | |||
# Compare the cookie controls and privacy settings provided by different web browsers. | |||
Experiments involving authentication cookies should only be performed on systems and accounts that the learner owns or has permission to test. | |||
== Discussion questions, essay ideas, and learning related AI prompt ideas == | |||
* Why does HTTP need mechanisms such as cookies if HTTP is largely stateless? | |||
* What useful website functions would become more difficult without cookies? | |||
* When does a useful cookie become a privacy concern? | |||
* What is the difference between a first-party and third-party cookie? | |||
* What security problems can result from poorly protected session cookies? | |||
* How do <code>Secure</code>, <code>HttpOnly</code>, and <code>SameSite</code> improve cookie security? | |||
* Should websites minimize the number and lifetime of cookies they create? | |||
* How have browser restrictions on third-party cookies changed online advertising? | |||
* Compare cookies with other forms of browser storage. | |||
* Ask an AI system to explain the complete lifecycle of a login cookie from initial authentication through logout. | |||
* Ask an AI system to design a small educational website that demonstrates session and persistent cookies without collecting unnecessary personal information. | |||
* Research what cookies are created by a MediaWiki installation and explain the purpose of each one. | |||
== Wikipedia readings == | |||
* [[w:HTTP cookie|HTTP cookie]] | |||
* [[w:HTTP|HTTP]] | |||
* [[w:Web storage|Web storage]] | |||
* [[w:Session (computer science)|Session]] | |||
* [[w:Web tracking|Web tracking]] | |||
* [[w:Third-party cookie|Third-party cookie]] | |||
* [[w:Cross-site request forgery|Cross-site request forgery]] | |||
* [[w:Cross-site scripting|Cross-site scripting]] | |||
* [[w:Internet privacy|Internet privacy]] | |||
== External readings == | |||
* [https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Cookies MDN: Using HTTP cookies] | |||
* [https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie MDN: Set-Cookie] | |||
* [https://www.rfc-editor.org/rfc/rfc6265 RFC 6265: HTTP State Management Mechanism] | |||
== See also == | |||
{{Col}} | |||
* [[HTTP]] | |||
* [[HTTPS]] | |||
* [[World Wide Web]] | |||
* [[Web browser]] | |||
* [[Web server]] | |||
* [[Web development]] | |||
* [[Authentication]] | |||
* [[Computer security]] | |||
{{break}} | |||
* [[Privacy]] | |||
* [[Internet privacy]] | |||
* [[Web analytics]] | |||
* [[Online advertising]] | |||
* [[MediaWiki]] | |||
* [[JavaScript]] | |||
* [[Cross-site scripting]] | |||
* [[Cross-site request forgery]] | |||
{{colend}} | |||
[[Category:World Wide Web]] | |||
[[Category:Internet]] | |||
[[Category:Web development]] | |||
[[Category:Computer security]] | |||
[[Category:Privacy]] | |||
[[Category:HTTP]] | |||
Latest revision as of 19:07, 29 September 2026
HTTP cookies are small pieces of data that a website can ask a web browser to store and later send back to the website. Cookies are an important part of how the modern World Wide Web works because the underlying HTTP protocol is largely stateless. Without some method of maintaining state, a website would otherwise have difficulty remembering that two separate requests came from the same browser or session.
Cookies can be used for useful functions such as keeping a person logged into a website, remembering preferences, maintaining a shopping cart, improving security, measuring website usage, and personalizing a website. Cookies can also be used for advertising and tracking, which has made them an important subject in discussions of privacy, computer security, and Internet regulation.
Learning about cookies can help people better understand what happens between a browser and a web server, how authentication works, and how websites can remember information between page requests.
How cookies work
A web server can send a cookie to a browser using the HTTP Set-Cookie response header.
A simplified example might look like:
Set-Cookie: session=abc123
The browser can store the cookie and return it to the appropriate website in later requests using the Cookie request header.
For example:
Cookie: session=abc123
The server can then associate abc123 with information stored on the server, such as a logged-in account or an active session.
The cookie itself does not necessarily contain all of the information about the user. A cookie may simply contain an identifier that corresponds with information maintained in a database on the server.
Common uses of cookies
Cookies have many possible uses.
|
|
A MediaWiki installation, for example, may use cookies to maintain login sessions and remember certain user preferences.
It is therefore inaccurate to describe cookies simply as tracking mechanisms. Tracking is one possible use of cookies, but many websites would lose important functionality if all cookies were removed.
Session and persistent cookies
Cookies can have different lifetimes.
A session cookie is generally intended to exist for the duration of a browser session. If a cookie does not specify an expiration time or maximum age, browsers normally treat it as a session cookie.
A persistent cookie contains an expiration time or maximum lifetime. It can remain stored after the browser is closed and may be available during a later visit.
Persistent cookies can be useful for features such as remembering login status or preferences.
They can also allow information about activity to remain associated with a browser for longer periods.
Cookie attributes
Cookies can include attributes that determine how and when they are used.
Important attributes include:
ExpiresorMax-Age, which can determine how long a cookie remains valid.Domain, which controls the domain scope of a cookie.Path, which limits the request paths for which a cookie is sent.Secure, which instructs the browser to send the cookie only through secure HTTPS connections, subject to browser rules.HttpOnly, which prevents ordinary JavaScript access to the cookie and can help protect sensitive cookies from some attacks.SameSite, which controls when cookies are sent in requests involving different sites.
The SameSite attribute can generally use values such as Strict, Lax, or None. Cookies using SameSite=None must also use Secure in modern browsers.
Many modern browsers apply a Lax or Lax-like behavior when SameSite is not explicitly specified.
First-party and third-party cookies
A distinction is often made between first-party cookies and third-party cookies.
A first-party cookie is associated with the site that a person is directly visiting.
A third-party cookie generally involves content or services provided by another site within the page being visited.
For example, a website might contain advertising, analytics, embedded video, or other resources provided by another company. Depending on the browser, technology, and privacy settings involved, those services may attempt to use cookies or other forms of storage.
Third-party cookies have historically been widely used for advertising and cross-site tracking. Browsers increasingly restrict third-party cookie behavior, and website developers should not assume that third-party cookies will always be available.
Cookies, privacy, and tracking
Cookies can create privacy concerns when they are used to build records of a person's activity across websites or over long periods of time.
However, deleting or blocking cookies does not necessarily prevent all forms of tracking.
Websites and third-party services may also use:
|
|
Privacy therefore involves more than managing cookies alone.
Users can generally inspect, block, or delete cookies through their browser. Browsers may also provide settings for preventing cross-site tracking or automatically deleting site data.
Cookies and computer security
Poor cookie configuration can create security problems.
Authentication cookies are particularly important because possession of a valid session cookie may allow a server to treat a browser as an authenticated user.
Developers can reduce some risks by using HTTPS, appropriate Secure and HttpOnly attributes, appropriate SameSite settings, limited cookie lifetimes, secure session management, and other computer security practices.
Cookies can also be relevant to attacks such as cross-site scripting, cross-site request forgery, and session fixation.
Cookie security should therefore be considered as part of a larger web application security strategy rather than as an isolated technical issue.
Learning activities
HTTP cookies are relatively easy to study directly using a modern web browser.
Possible activities include:
- Open the browser developer tools and examine the cookies stored by several websites.
- Compare session cookies with persistent cookies.
- Examine the
Secure,HttpOnly, andSameSiteattributes of different cookies. - Delete a website's cookies and observe which features change.
- Log into a test website and observe when authentication cookies are created and removed.
- Use a local web server to experiment with different
Set-Cookieheaders. - Compare the cookie controls and privacy settings provided by different web browsers.
Experiments involving authentication cookies should only be performed on systems and accounts that the learner owns or has permission to test.
Discussion questions, essay ideas, and learning related AI prompt ideas
- Why does HTTP need mechanisms such as cookies if HTTP is largely stateless?
- What useful website functions would become more difficult without cookies?
- When does a useful cookie become a privacy concern?
- What is the difference between a first-party and third-party cookie?
- What security problems can result from poorly protected session cookies?
- How do
Secure,HttpOnly, andSameSiteimprove cookie security? - Should websites minimize the number and lifetime of cookies they create?
- How have browser restrictions on third-party cookies changed online advertising?
- Compare cookies with other forms of browser storage.
- Ask an AI system to explain the complete lifecycle of a login cookie from initial authentication through logout.
- Ask an AI system to design a small educational website that demonstrates session and persistent cookies without collecting unnecessary personal information.
- Research what cookies are created by a MediaWiki installation and explain the purpose of each one.
Wikipedia readings
- HTTP cookie
- HTTP
- Web storage
- Session
- Web tracking
- Third-party cookie
- Cross-site request forgery
- Cross-site scripting
- Internet privacy