Skip to content

fix: flush queued cookies between requests in LaravelHttpServer - #257

Merged
MrPunyapal merged 2 commits into
pestphp:5.xfrom
cyppe:fix/flush-queued-cookies-per-request
Sep 14, 2026
Merged

MrPunyapal merged 2 commits into
pestphp:5.xfrom
cyppe:fix/flush-queued-cookies-per-request

Conversation

@cyppe

@cyppe cyppe commented Sep 10, 2026

Copy link
Copy Markdown

Problem

LaravelHttpServer serves every request of a browser test from one long-lived container. Cookies queued through Cookie::queue() land in the CookieJar singleton, and AddQueuedCookiesToResponse attaches every queued cookie to a response but never removes it from the jar. Nothing else does either:

  • FPM discards the jar with the process;
  • Octane flushes it between requests;
  • the in-process test server keeps it for the whole test.

So a cookie queued by the first request is re-sent on every later response of the same test, including responses of routes that never queued anything.

Impact

A browser test cannot verify which response hands a cookie to the browser, and a cookie a page deliberately queues once (for example a first-party attribution cookie written on the first page after consent) shows up on every Livewire/XHR response afterwards. It also masks application bugs: code that forgets to queue a cookie on a later page still "works" in the test because the stale queue is replayed. We hit this while testing a consent-dependent cookie hand-over in a Laravel app: the assertion "exactly one response carried the cookie" saw five.

Fix

Flush the jar before handling each request, next to the existing forgetScopedInstances() (same per-request lifecycle FPM and Octane provide):

app()->make(CookieJar::class)->flushQueuedCookies();

Test

it does not re-send a cookie queued in an earlier request records the Set-Cookie headers of two requests through RequestHandled: the first route queues a cookie, the second does not. On the unfixed source the cookie appears on both responses (['queue-cookie', 'no-cookie']); with the fix only on the first.

Run: vendor/bin/pest tests/Unit/Drivers/Laravel/LaravelHttpServerTest.php (6 passed).

cyppe and others added 2 commits September 10, 2026 11:42
The in-process server reuses one container, so the CookieJar singleton kept every
cookie queued through Cookie::queue() and AddQueuedCookiesToResponse re-sent it
on every later response of the same test. FPM discards the jar with the process
and Octane flushes it per request; do the same before handling each request.
@MrPunyapal
MrPunyapal merged commit a78ede5 into pestphp:5.x Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants