Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Support non-security cookie parameters in @effect/openapi-generator HttpClient output

Open
#8,845 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
48/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
node.js, typescript
Domain
api

Research direction

Start with the parser in packages/tools/openapi-generator/src/OpenApiGenerator.ts, which the issue identifies as emitting the warning, and trace how in: "cookie" parameters are represented in generated httpclient operations and requests. Use the provided reproduction to verify the generated input and request behavior. Done means ordinary cookie parameters retain their types and requiredness and have a supported server-side sending path without assuming browsers can set a Cookie header.

Written by the indexing model from the issue text.

Description

What is the problem this feature would solve?

@effect/[email protected] drops ordinary OpenAPI parameters declared with in: "cookie" when generating format: "httpclient" output. It emits cookie-parameter-dropped, but even a required cookie is omitted from both the generated operation input and request construction.

For server-side consumers, this means the generated method does not represent the full request contract, and cookies must be supplied separately through the HTTP client. Ordinary cookies such as a locale preference should not need to be modeled as authentication security schemes.

The warning is intentional in the current parser. This is a request to extend support.

Minimal reproduction

Verified with Node.js v26.10.0 on macOS arm64 and these exact dependencies:

pnpm add [email protected] @effect/[email protected] @effect/[email protected]

Save the following as repro.mjs, then run node repro.mjs:

import { Effect } from 'effect'
import * as OpenApiGenerator from '@effect/openapi-generator/OpenApiGenerator'

const spec = {
  openapi: '3.0.3',
  info: { title: 'Cookie parameter example', version: '1.0.0' },
  paths: {
    '/greeting': {
      get: {
        operationId: 'getGreeting',
        parameters: [
          {
            name: 'locale',
            in: 'cookie',
            required: true,
            schema: { type: 'string' },
          },
        ],
        responses: { '204': { description: 'No content' } },
      },
    },
  },
}

const warnings = []
const generated = await Effect.runPromise(
  Effect.gen(function* () {
    const generator = yield* OpenApiGenerator.OpenApiGenerator
    return yield* generator.generate(spec, {
      format: 'httpclient',
      name: 'ExampleClient',
      onWarning: (warning) => warnings.push(warning),
    })
  }).pipe(Effect.provide(OpenApiGenerator.layerTransformerSchema)),
)

console.log(JSON.stringify(warnings, null, 2))
console.log(generated)

The process exits successfully and reports:

[
  {
    "code": "cookie-parameter-dropped",
    "message": "Cookie parameter \"locale\" was dropped because non-security cookie parameters are not supported.",
    "path": "/greeting",
    "method": "get",
    "operationId": "getGreeting"
  }
]

The generated getGreeting method accepts only the response config option. It has no locale input and does not serialize a cookie into the request, despite required: true in the specification.

What is the feature you are proposing to solve the problem?

Preserve ordinary cookie parameter types and requiredness in the generated operation inputs, with a supported way to send those values in server-side HTTP clients.

Please account for browser restrictions: browser cookies are managed by the browser, so explicitly setting a Cookie header is not a portable implementation. A documented runtime-aware option or integration hook would also help.

What alternatives have you considered?
  • Configure cookie headers or a cookie jar on the underlying HTTP client. This can handle transport, but the generated method still loses the per-operation parameter type and requiredness.
  • Use browser-managed cookies where applicable. This does not cover server-side callers.
  • Declare genuine authentication cookies as security schemes. This is not an appropriate model for ordinary parameters such as the locale cookie in the example.
Dominant language
TypeScript
Stars
16.7k
Forks
808
Avg merge
11h 29m
Merged PRs (30d)
453

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Effect-TS/effect

All issues in Effect-TS/effect

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.