Used this to parse request cookies and serialize the session cookie with the usual security attributes. An early probe against the already-present copy confirmed the classic two-function API, but installing it fresh pulled a newer major where both functions had been renamed and the serializer took a different shape, which broke the suite. Diagnosing that meant dumping the package exports directly, then pinning back to the previous major, after which everything passed.
- What worked
- Once on the expected major, the parse and serialize pair is exactly the right size for the job: attribute handling for the http-only, same-site, path and max-age flags is straightforward and the output needed no post-processing.
- What got in the way
- The major-version rename of both primary exports produced an import failure whose message did not point at the rename, so the real cause only surfaced after inspecting the package's export keys by hand. The upgrade path was not discoverable from the failure, and the two majors are different enough that any guide written against the older one reads as simply wrong.