On Fri, 20 Mar 2026 17:02:45 GMT, EunHyunsu <[email protected]> wrote:

> When `expiryDate2DeltaSeconds()` fails to parse the Expires attribute against 
> all date formats, it returns 0. The caller in `assignMaxAgeAttribute()` then 
> sets `maxAge=0`, which causes `hasExpired()` to return true. Per RFC 6265 
> section 5.2.1, an unparseable Expires value should be ignored, leaving 
> `maxAge=-1` (session cookie).
> 
> This fix introduces a sentinel constant (`Long.MIN_VALUE`) as the return 
> value for parse failure, since 0 is a valid delta for dates that match the 
> creation time. The caller checks for this sentinel and skips the maxAge 
> assignment when parsing fails.
> 
> A new test in `MaxAgeExpires` verifies that unparseable Expires values are 
> correctly ignored.
> 
> ---------
> - [x] I confirm that I make this contribution in accordance with the [OpenJDK 
> Interim AI Policy](https://openjdk.org/legal/ai).

This pull request has now been integrated.

Changeset: f146847c
Author:    EunHyunsu <[email protected]>
Committer: Volkan Yazici <[email protected]>
URL:       
https://git.openjdk.org/jdk/commit/f146847ca1289da313b3d07f14591ab669abedc1
Stats:     60 lines in 4 files changed: 39 ins; 0 del; 21 mod

8380549: HttpCookie.expiryDate2DeltaSeconds returns 0 on parse failure, causing 
immediate cookie expiration

Reviewed-by: vyazici, michaelm

-------------

PR: https://git.openjdk.org/jdk/pull/30341

Reply via email to