Skip to documentation content

Cookies

Cookies

The cookies object and methods for reading, setting, and unsetting cookies.

{{ cookies }}

The cookies object is available on every page, and contains information regarding the cookies sent with the request. Note that this will typically only include cookies for the current or top-level domain on multi-domain sites.

Properties
Properties of {{ cookies }} objects
Name Type Description
object_type string Will always be cookies
is_valid boolean Will always be true
keys list The list of cookie names on the current request, including cookies that may have been added or removed after the request started processing.
* string Individual cookies on this request may be accessed using {{ cookies.cookieName }} or {{ cookies['cookie-name'] }} syntax
output string JSON representation of the cookies object, similar to {{ cookies | inspect: 3, false }}

The cookies object is copyable, and when copied using the {% copy_to_dictionary %} the keys will be the names of the cookies and the values will be the corresponding cookie objects. You may also treat this object as a list containing all of the cookie names which may be iterated using a {% for %} loop.

Example Read a custom cookie by name (with optional fallback)Use the cookies object and default filter to read a cookie, with an alternate name as fallback.
Liquid
{%- var cookieValue = cookies.customCookieName | default: cookies['alternate-cookie-name'] -%}
{%- if cookieValue is_valid -%}
	<p>Do something with {{ cookieValue }}</p>
{%- endif -%}
Example How to use the set_cookie method

Set a cookie that expires in 20 minutes

Liquid
{%- var expiresDate = "now" | add_minutes: 20 -%}
{%- set_cookie loginsection "lastsection=accounts" expires:expiresDate path:"/protected" domain:".parentdomain.com" -%}

This example demonstrates the use of the expires, path, and domain parameters of the set_cookie method.

Set a cookie with a reference variable

Liquid
{%- var sectioncookie = 'accountspage' -%}
{%- var sectioncount = cookies[sectioncookie] | to_int | plus: 1 -%}
{%- set_cookie &sectioncookie sectioncount -%}

This example demonstrates the use of a reference variable to set a cookie with a dynamic name.

Set a cookie with a custom statistics string

Liquid
{%- if session.allowed and permissions.allow_public_statistics -%}
	{%- capture statisticsString -%}
SessionStart: {{session.start_date | date: 'MMMM dd, yyyy, H:mm:ss'-}}
SessionRequests: {{session.num_requests-}}
LastRequest: {{request.date | date: 'MMMM dd, yyyy, H:mm:ss'-}}
<<Add other custom statistics here>>
	{%- endcapture -%}
	{%- set_cookie site_statistics statisticsString -%}
{%- endif -%}

Checks if the "allow_public_statistics" custom permission has been set, and if it has gathers information about the current session statistics for storage in a "site_statistics" cookie - presumably for display using javascript on the site.

Example List all cookies in the current requestIterate over request.cookies and output each cookie name and value (via cookies[name]).
Liquid
<h4>Cookies:</h4>
<ul>
{%- for cookie in request.cookies -%}
	<li><strong>{{cookie}}</strong> = {{cookies[cookie]}}</li>
{%- endfor -%}
</ul>

{% set_cookie %}

Sets a cookie in the HTTP response.

{% set_cookie cookie_name cookie_value attributes %}
Parameters
cookie_name requiredvariable
The name of the cookie to set. May be a reference variable
cookie_value requiredstring
attributes optionaldictionary
Key:value pairs with unique keys. May use the variable arguments syntax. Additional directives to use when setting the cookie

Options

expires optionalvalue
Expiration date/time
path optionalvalue
Cookie path
domain optionalvalue
Cookie domain
secure optionalvalue
True to set the secure flag on the cookie
httponly optionalvalue
True to set the httponly flag on the cookie

There are a small number of reserved and forbidden cookie names, the most prominent being "_mp_permissions" - the name of the cookie used by Marketpath for handling permissions. You must use the {% set_client_permission %} and {% unset_client_permission %} methods to manage permissions instead of manipulating the permissions cookie directly.

Example How to use the set_cookie method

Set a cookie that expires in 20 minutes

Liquid
{%- var expiresDate = "now" | add_minutes: 20 -%}
{%- set_cookie loginsection "lastsection=accounts" expires:expiresDate path:"/protected" domain:".parentdomain.com" -%}

This example demonstrates the use of the expires, path, and domain parameters of the set_cookie method.

Set a cookie with a reference variable

Liquid
{%- var sectioncookie = 'accountspage' -%}
{%- var sectioncount = cookies[sectioncookie] | to_int | plus: 1 -%}
{%- set_cookie &sectioncookie sectioncount -%}

This example demonstrates the use of a reference variable to set a cookie with a dynamic name.

Set a cookie with a custom statistics string

Liquid
{%- if session.allowed and permissions.allow_public_statistics -%}
	{%- capture statisticsString -%}
SessionStart: {{session.start_date | date: 'MMMM dd, yyyy, H:mm:ss'-}}
SessionRequests: {{session.num_requests-}}
LastRequest: {{request.date | date: 'MMMM dd, yyyy, H:mm:ss'-}}
<<Add other custom statistics here>>
	{%- endcapture -%}
	{%- set_cookie site_statistics statisticsString -%}
{%- endif -%}

Checks if the "allow_public_statistics" custom permission has been set, and if it has gathers information about the current session statistics for storage in a "site_statistics" cookie - presumably for display using javascript on the site.

{% unset_cookie %}

"Unsets" one or more cookies. Because of how cookies work, this will actually ADD the cookie to the response with an expiration date in the past.

{% unset_cookie names %}
Parameters
names requiredlist
One or more values. May use the variable arguments syntax. The names of the cookies to unset
Example How to use the unset_cookie method

Unset Cookie

Liquid
{%- if cookie.advertising_id -%}
	{%- unless permissions.allow_advertising -%}
		{%- unset_cookie advertising_id advertising_alt_id -%}
	{%- endunless -%}
{%- endif -%}

If the "advertising_id" cookie has been set and the "allow_advertising" permission has NOT been granted, use the unset_cookie method to clear both the "advertising_id" and "advertising_alt_id" cookies.

Unset multiple Cookies

Liquid
{%- var unset_cookies = request.query_params.unsetcookies | split: ',' -%}
{%- for cookie in unset_cookies -%}
	{%- var cookie_alt = cookie | append:'-alt' -%}
	{%- unset_cookie &cookie &cookie_alt -%}
{%- endfor -%}

Checks if the "unsetcookies" query parameter was included in the request, and for each comma-delimited cookie name to unset, unset both the specified cookie and the "-alt" version of the cookie if it exists by using the unset_cookie method with two reference variables.