逗號禁止在cookie值rfc6265:
cookie-header = "Cookie:" OWS cookie-string OWS
cookie-string = cookie-pair *(";" SP cookie-pair)
cookie-pair = cookie-name "=" cookie-value
cookie-value = *cookie-octet/(DQUOTE *cookie-octet DQUOTE)
cookie-octet = %x21/%x23-2B/%x2D-3A/%x3C-5B/%x5D-7E
; US-ASCII characters excluding CTLs,
; whitespace DQUOTE, comma, semicolon,
; and backslash
UPDATE但是後面沒有瀏覽器的這個標準。在我的練習中,通過逗號可能會跳出cookie-octet
DQUOTE
(此cookie通過Java EE Cookie對象引用服務器端):
Cookie: auth="USER,password,2014-01-01"; lang=EN
Cookie: auth="USER,password,2014-01-01"; lang=EN