# Setting a cookie in http.jl so as to start a session

**URL:** <https://discourse.julialang.org/t/setting-a-cookie-in-http-jl-so-as-to-start-a-session/88572>\
**Category:** Web Stack\
**Created:** [October 11, 2022, 11:37am UTC](https://discourse.julialang.org/t/setting-a-cookie-in-http-jl-so-as-to-start-a-session/88572 "2022-10-11T11:37:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![grahamstark](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/grahamstark/32/5200_2.png) [@grahamstark](https://discourse.julialang.org/u/grahamstark)\
**Post date:** [October 11, 2022, 11:37am UTC](https://discourse.julialang.org/t/setting-a-cookie-in-http-jl-so-as-to-start-a-session/88572/1 "2022-10-11T11:37:20Z")

</div>

Hi,

I appreciate this will seem obvious to those in the know, but could someone post an example of how to add a cookie server-side to a response that can be used as a session identifier? As a kind of middleware, I think. There doesn’t appear to be exactly that in the docs or this forum. I’m afraid I can’t post a MWE of me failing to get this to work as I’m on my phone ATM.

Many thanks,

Graham

---

<div class="post-metadata">

**Author:** ![quinnj](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/quinnj/32/11_2.png) [@quinnj](https://discourse.julialang.org/u/quinnj)\
**Post date:** [October 20, 2022, 2:27am UTC](https://discourse.julialang.org/t/setting-a-cookie-in-http-jl-so-as-to-start-a-session/88572/2 "2022-10-20T02:27:50Z")

</div>

You could do something like:

```julia
using UUIDs, HTTP

const SESSION_IDS = Set{UUID}()

function generate_and_set_session_id_middleware(handler)
    function (req::HTTP.Request)
        # first we pass the request on to the next handler in the chain
        resp = handler(req)
        # now that we have a response, we can generate and set the session id cookie
        session_id = uuid4()
        push!(SESSION_IDS, session_id)
        HTTP.setheader(resp, "Set-Cookie" => "MyApplicationSessionId=$session_id;")
        return resp
    end
end

```

You could take it a step further and use the `HTTP.Cookie` object if you want, where you can set the expires, domain, path, etc. and then set that in the response.
