Flask Academy · 课时

在响应中设置自定义 Cookie

使用 set_cookie 和选项写入 Cookie

第 3 / 4 课13 个步骤

在响应中设置自定义 Cookie 是 CoddyKit 上的免费 Flask Academy 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Flask Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Flask Academy 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Cookies Beyond Sessions

Sometimes you want your own cookie, separate from the session, to remember a theme or a preference for a visitor. 🍪

You Need a Response

Cookies are written onto a response object. So first build one with make_response instead of returning a plain string.

from flask import make_response
resp = make_response('Hi there')

Call set_cookie

Add the cookie with set_cookie, passing a name and a value. Then return that response so the header reaches the browser.

resp.set_cookie('theme', 'dark')
return resp

Read It Next Time

On the next request the browser sends it back. Read your cookie from request.cookies, which works like a dictionary.

from flask import request
theme = request.cookies.get('theme')

Control the Lifetime

Set max_age in seconds to control how long a cookie survives. Leave it out and the cookie dies when the browser closes.

resp.set_cookie('theme', 'dark', max_age=60*60*24)

HTTPS Only

The secure flag tells the browser to send the cookie only over HTTPS, keeping it off plain unencrypted connections.

resp.set_cookie('token', 'abc', secure=True)

Hide from JavaScript

Turn on httponly so client-side scripts cannot read the cookie. This blocks a common cross-site scripting theft path.

resp.set_cookie('token', 'abc', httponly=True)

Limit Cross-Site Sending

The samesite option controls when the cookie travels on cross-site requests. Set it to Lax or Strict to curb CSRF risk.

resp.set_cookie('id', '7', samesite='Lax')

Deleting a Cookie

To remove one, call delete_cookie with its name on the response. The browser then drops it on the next visit.

resp.delete_cookie('theme')

Values Are Strings

Cookie values are always strings. To store a number or flag, convert it on the way out and parse it on the way back in.

resp.set_cookie('count', str(5))

Mind the Size

Browsers cap each cookie near four kilobytes. Keep them tiny and store large data on the server, referenced by an id.

Quick Check

You want a cookie that JavaScript on the page cannot read.

Recap

You learned to build a response, write cookies with set_cookie, read them from request.cookies, and harden them with secure flags. 🛡️

免费开始

用 AI 导师学习 Python — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
30
课程
120

常见问题解答

「在响应中设置自定义 Cookie」课时是免费的吗?

是的 — 「在响应中设置自定义 Cookie」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Flask Academy 课程的其余内容,请升级到 CoddyKit PRO。 Flask Academy 课程共包含 4 节课。

「在响应中设置自定义 Cookie」这节课中我会学到什么?

使用 set_cookie 和选项写入 Cookie 你通过在浏览器中直接运行的动手代码来练习 Flask Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Flask Academy 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Flask Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。

「在响应中设置自定义 Cookie」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Flask Academy 课中编写并运行代码吗?

能。每节 Flask Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 设置并读取 session 字典
  2. SECRET_KEY 与签名 Cookie
  3. 在响应中设置自定义 Cookie
  4. 请求之间的 Flash 消息
← 返回 Flask Academy