कुकीज़
कुकी छोटा टेक्स्ट है जो ब्राउज़र मिलती साइट की रिक्वेस्ट में जोड़ सकता है। पेज theme=dark लिखकर theme / dark दिखाता है; JavaScript-पठनीय कुकी में password या access token न रखें।
वेब स्टोरेज नहीं
localStorage में saved / lida / tea था। कुकी केवल अपनी site और path की रिक्वेस्ट में जा सकती है, हर site पर नहीं। document.cookie semicolon वाली string है, object नहीं।
पसंद
Path=/ theme को साइट के paths पर उपलब्ध करता है। SameSite=Lax cross-site स्थितियाँ सीमित करता है और Secure केवल HTTPS पर भेजता है।
document.cookie = "theme=dark; Path=/; SameSite=Lax; Secure";
console.log(document.cookie);
string में कई pairs हो सकते हैं, इसलिए उसे पूरे theme=dark से compare न करें।
नाम पढ़ना
; पर split करें, name के बाद = खोजें और value पर decodeURIComponent लगाएँ।
function readCookie(name) {
const start = name + "=";
const pair = document.cookie
.split("; ")
.find((part) => part.startsWith(start));
return pair ? decodeURIComponent(pair.slice(start.length)) : null;
}
console.log(readCookie("theme"));
console.log(readCookie("drink"));
आउटपुट dark, फिर null है। drink लिखा ही नहीं था और missing नाम error नहीं देता।
एन्कोड करें
; और = कुकी syntax हैं। tea / regular लिखने से पहले encodeURIComponent करें।
पढ़ने पर tea / regular लौटता है; raw semicolon नया भाग शुरू कर देगा।
📊 Cookie and localStorage
| Bedarf | Cookie | localStorage |
|---|---|---|
| Bei passenden Anfragen | oft ja | nein |
| Für Seiten-JavaScript lesbar | außer HttpOnly | ja |
| Kleine Präferenz | möglich | meist einfacher |
| Sensible Sitzungs-ID | Server: HttpOnly + Secure | nicht hier speichern |
चुनाव
Cookie और localStorage, पेज पर चल रहे असुरक्षित JavaScript से secret नहीं बचाते।
HttpOnly को JavaScript न set कर सकती है न पढ़ सकती है; server उसे Set-Cookie में भेजता है।
<!DOCTYPE html>
<html>
<body>
<p id="line">…</p>
<script>
document.cookie = "theme=dark; Path=/; SameSite=Lax; Secure";
function readCookie(name) {
const start = name + "=";
const pair = document.cookie.split("; ")
.find((part) => part.startsWith(start));
return pair ? decodeURIComponent(pair.slice(start.length)) : null;
}
document.querySelector("#line").textContent =
"theme / " + readCookie("theme");
</script>
</body>
</html>
पंक्ति
पेज dark save करता है, theme पढ़ता है और टेक्स्ट बनाता है।
पंक्ति theme / dark है। साधारण HTTP पर Secure कुकी अस्वीकार हो सकती है; live site HTTPS है।
अभ्यास
Path=/ के साथ theme लिखें, drink पढ़ें, tea / regular encode करें, HttpOnly Secure SameSite बताएँ और पंक्ति पढ़ें।
भूलें और सार
cookie को object या secret box न मानें। संवेदनशील session identifier server से HttpOnly, Secure और SameSite के साथ आता है।
🧠 अपने ज्ञान की परीक्षा करें
अपने ज्ञान की परीक्षा करें
इस इंटरैक्टिव क्विज़ के साथ अपनी चुनौती लें और देखें कि आप विषय को कितनी अच्छी तरह समझते हैं
📝 निर्देश
- हर प्रश्न को ध्यान से पढ़ें
- हर प्रश्न के लिए सबसे अच्छा उत्तर चुनें
- आप जितनी बार चाहें क्विज़ दोबारा दे सकते हैं
- आपकी प्रगति शीर्ष पर दिखाई जाएगी