On Fri, 20 Mar 2026 17:02:45 GMT, EunHyunsu <[email protected]> wrote:
> When `expiryDate2DeltaSeconds()` fails to parse the Expires attribute against > all date formats, it returns 0. The caller in `assignMaxAgeAttribute()` then > sets `maxAge=0`, which causes `hasExpired()` to return true. Per RFC 6265 > section 5.2.1, an unparseable Expires value should be ignored, leaving > `maxAge=-1` (session cookie). > > This fix introduces a sentinel constant (`Long.MIN_VALUE`) as the return > value for parse failure, since 0 is a valid delta for dates that match the > creation time. The caller checks for this sentinel and skips the maxAge > assignment when parsing fails. > > A new test in `MaxAgeExpires` verifies that unparseable Expires values are > correctly ignored. > > --------- > - [x] I confirm that I make this contribution in accordance with the [OpenJDK > Interim AI Policy](https://openjdk.org/legal/ai). This pull request has now been integrated. Changeset: f146847c Author: EunHyunsu <[email protected]> Committer: Volkan Yazici <[email protected]> URL: https://git.openjdk.org/jdk/commit/f146847ca1289da313b3d07f14591ab669abedc1 Stats: 60 lines in 4 files changed: 39 ins; 0 del; 21 mod 8380549: HttpCookie.expiryDate2DeltaSeconds returns 0 on parse failure, causing immediate cookie expiration Reviewed-by: vyazici, michaelm ------------- PR: https://git.openjdk.org/jdk/pull/30341
