Support non-security cookie parameters in @effect/openapi-generator HttpClient output
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 48/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- node.js, typescript
- Domain
- api
Research direction
Start with the parser in packages/tools/openapi-generator/src/OpenApiGenerator.ts, which the issue identifies as emitting the warning, and trace how in: "cookie" parameters are represented in generated httpclient operations and requests. Use the provided reproduction to verify the generated input and request behavior. Done means ordinary cookie parameters retain their types and requiredness and have a supported server-side sending path without assuming browsers can set a Cookie header.
Written by the indexing model from the issue text.
Description
What is the problem this feature would solve?
@effect/[email protected] drops ordinary OpenAPI parameters declared with in: "cookie" when generating format: "httpclient" output. It emits cookie-parameter-dropped, but even a required cookie is omitted from both the generated operation input and request construction.
For server-side consumers, this means the generated method does not represent the full request contract, and cookies must be supplied separately through the HTTP client. Ordinary cookies such as a locale preference should not need to be modeled as authentication security schemes.
The warning is intentional in the current parser. This is a request to extend support.
Minimal reproduction
Verified with Node.js v26.10.0 on macOS arm64 and these exact dependencies:
pnpm add [email protected] @effect/[email protected] @effect/[email protected]
Save the following as repro.mjs, then run node repro.mjs:
import { Effect } from 'effect'
import * as OpenApiGenerator from '@effect/openapi-generator/OpenApiGenerator'
const spec = {
openapi: '3.0.3',
info: { title: 'Cookie parameter example', version: '1.0.0' },
paths: {
'/greeting': {
get: {
operationId: 'getGreeting',
parameters: [
{
name: 'locale',
in: 'cookie',
required: true,
schema: { type: 'string' },
},
],
responses: { '204': { description: 'No content' } },
},
},
},
}
const warnings = []
const generated = await Effect.runPromise(
Effect.gen(function* () {
const generator = yield* OpenApiGenerator.OpenApiGenerator
return yield* generator.generate(spec, {
format: 'httpclient',
name: 'ExampleClient',
onWarning: (warning) => warnings.push(warning),
})
}).pipe(Effect.provide(OpenApiGenerator.layerTransformerSchema)),
)
console.log(JSON.stringify(warnings, null, 2))
console.log(generated)
The process exits successfully and reports:
[
{
"code": "cookie-parameter-dropped",
"message": "Cookie parameter \"locale\" was dropped because non-security cookie parameters are not supported.",
"path": "/greeting",
"method": "get",
"operationId": "getGreeting"
}
]
The generated getGreeting method accepts only the response config option. It has no locale input and does not serialize a cookie into the request, despite required: true in the specification.
What is the feature you are proposing to solve the problem?
Preserve ordinary cookie parameter types and requiredness in the generated operation inputs, with a supported way to send those values in server-side HTTP clients.
Please account for browser restrictions: browser cookies are managed by the browser, so explicitly setting a Cookie header is not a portable implementation. A documented runtime-aware option or integration hook would also help.
What alternatives have you considered?
- Configure cookie headers or a cookie jar on the underlying HTTP client. This can handle transport, but the generated method still loses the per-operation parameter type and requiredness.
- Use browser-managed cookies where applicable. This does not cover server-side callers.
- Declare genuine authentication cookies as security schemes. This is not an appropriate model for ordinary parameters such as the
localecookie in the example.
- Dominant language
- TypeScript
- Stars
- 16.7k
- Forks
- 808
- Avg merge
- 11h 29m
- Merged PRs (30d)
- 453
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Effect-TS/effect
-
Difficulty 1/5 1-3 hours Newbie friendliness 86/100
Effect-TS/effect#8863 · 1 comment ·
Maintainers usually reply within 1 day
-
BrowserWorkerRunner: port finalizer throws when the worker global has no close() (Bun)Possibly taken @santiago-ramos-02 claimed this 8 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Effect-TS/effect#8635 · 3 comments ·
Maintainers usually reply within 1 day
-
Support {self: this} for fnUntracedMay be free again @ArjunCodess claimed this 19 days ago, and no pull request is open. Openenhancement
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Effect-TS/effect#8101 · 1 comment ·
Maintainers usually reply within 1 day
-
Support delayed jobs in PersistedQueuePossibly taken @tim-smart claimed this today. Openenhancement
Difficulty 5/5 Over a week Newbie friendliness 25/100
Maintainers usually reply within 1 day
-
ChildProcess: support bidirectional (duplex) additional file descriptorsPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 3/5 Half a day Newbie friendliness 25/100
Maintainers usually reply within 1 day
All issues in Effect-TS/effect
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
siyuan-note/siyuan#20313 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
alunduil/projects-v2-sync#14 ·
-
Service process inherits the caller's cwd at first use, holding that folder open on Windows (EBUSY)Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
DevTools page styles leak into the host app in developmentPossibly taken @onmax claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
nuxt-modules/better-auth#567 · 1 comment ·
Maintainers usually reply within 1 day