FrostMVC\Cookie
use FrostMVC\Cookie;
Cookie helper that hashes cookie names and stores metadata as JSON values.
When encryption is enabled (the default), cookie names are passed through MD5 before being set or read, which obscures their meaning to end users.
Cookie values are stored as JSON objects containing name, value, and other metadata so they can be retrieved by get() as typed objects. The SameSite attribute defaults to the browser default unless explicitly set on the Cookie instance or via the static set() helper.
| Property | Type | Description |
|---|---|---|
| $name | mixed |
|
| $value | mixed |
|
| $expire | mixed |
|
| $path | mixed |
|
| $domain | mixed |
|
| $secure | mixed |
|
| $httponly | mixed |
|
| $samesite | mixed |
| ::check() | Returns true when the decoded value of the named cookie equals one of the provided values. Uses strict comparison. |
| ->createCookie() | Sets this cookie instance on the client using the configured properties. The cookie value is a JSON-encoded metadata object. |
| ::get() | Reads a cookie by its logical name and returns the decoded metadata object. Returns false when the cookie is not present. |
| ::remove() | Deletes a cookie by expiring it immediately. Returns true if the cookie was present and removed, false if it did not exist. |
| ::set() | Sets a cookie with all standard attributes in a single call. Uses the PHP 7.3+ options-array form of setcookie() so that SameSite is correctly included in the Set-Cookie header. |
| ::setEncryptID() | Controls whether cookie names are hashed with MD5 before being sent. Enabled by default. Disable only when cookie names must be readable. |
Cookie::check($what, ...$value)
Returns true when the decoded value of the named cookie equals one of the provided values. Uses strict comparison.
| $what | string |
Logical cookie name. |
| ...$value | mixed |
One or more values to match against. |
bool
$cookie->createCookie()
Sets this cookie instance on the client using the configured properties. The cookie value is a JSON-encoded metadata object.
string The (possibly hashed) cookie name as sent to the client.
Cookie::get($name)
Reads a cookie by its logical name and returns the decoded metadata object. Returns false when the cookie is not present.
| $name | string |
Logical cookie name. |
object|false
Cookie::remove($name)
Deletes a cookie by expiring it immediately. Returns true if the cookie was present and removed, false if it did not exist.
| $name | string |
Logical cookie name. |
bool
Cookie::set($name, $value, $expire = 0, $path = '', $domain = '', $secure = false, $httponly = false, $samesite = null)
Sets a cookie with all standard attributes in a single call. Uses the PHP 7.3+ options-array form of setcookie() so that SameSite is correctly included in the Set-Cookie header.
| $name | string |
Logical cookie name (hashed if encryption is on). |
| $value | mixed |
The value to store. |
| $expire | int |
Unix timestamp for expiry. 0 = session cookie. Default:0 |
| $path | string |
Cookie path scope. Default:'' |
| $domain | string |
Cookie domain scope. Default:'' |
| $secure | bool |
Transmit over HTTPS only. Default:false |
| $httponly | bool |
Inaccessible to JavaScript. Default:false |
| $samesite | string|null |
'Strict', 'Lax', or 'None'. Null uses browser default. Default:null |
Cookie::setEncryptID($encrypt = true)
Controls whether cookie names are hashed with MD5 before being sent. Enabled by default. Disable only when cookie names must be readable.
| $encrypt | bool |
Default: true |
Generated from core/classes/Cookie.php (FrostMVC ).