//ShowAllTasksFunc is used to handle the "/" URL which is the default ons func ShowAllTasksFunc(w http.ResponseWriter, r *http.Request){ if r.Method == "GET" { context := db.GetTasks("pending") //true when you want non deleted notes if message != "" { context.Message = message } context.CSRFToken = "abcd" message = "" expiration := time.Now().Add(365 * 24 * time.Hour) cookie := http.Cookie{Name: "csrftoken",Value:"abcd",Expires:expiration} http.SetCookie(w, &cookie) homeTemplate.Execute(w, context) } else { message = "Method not allowed" http.Redirect(w, r, "/", http.StatusFound) } } 
RequestsResponseWriter
 Host: 127.0.0.1:8081 User-Agent: ... Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate DNT: 1 Referer: http://127.0.0.1:8081/ Cookie: csrftoken=abcd Connection: keep-alive 

并且处理器会发送一个响应,如下所示:

 Content-Type: text/html; charset=utf-8 Date: Tue, 12 Jan 2016 16:43:53 GMT Set-Cookie: csrftoken=abcd; Expires=Wed, 11 Jan 2017 16:43:53 GMT Transfer-Encoding: chunked <html>...</html> 

当浏览器发出请求时,它将包含该域的cookie,因为cookie存储在域中,并且不能从跨域访问,如果将cookie设置为HTTP,则只能从网站设置它通过HTTP而不是通过JS。

所以从cookies获取信息时,可以使用r.Cookie方法来做到这一点

 cookie, _ := r.Cookie("csrftoken") if formToken == cookie.Value { 

但是当你要设置一个cookie的时候,你必须在响应编写器方法中完成这个请求,这个请求是一个我们回应的只读对象,把它看作是从某个人那里得到的文本消息,也就是一个请求,你只能得到它,你键入的是一个响应,所以你可以在input一个cookie

有关更多详细信息: https : //thewhitetulip.gitbooks.io/webapp-with-golang-anti-textbook/content/content/2.4workingwithform.html