Keep neoirc-cli sessions on localhost and test the relay goroutine stop
check / check (push) Failing after 5s
check / check (push) Failing after 5s
The auth cookie is always Secure, and Go 1.24's cookie jar sends a Secure cookie only over HTTPS, so neoirc-cli lost its session against a plain-HTTP server on localhost. Its jar now treats a server on localhost as HTTPS, as curl does. The README's Transport Security section and Python example say what a client needs. A test checks that closing a registered IRC client's connection stops its relay goroutine. The README Entrypoints section names a make target only for the scripts that have one, and the Dockerfile says why the test phase runs with -p 4. Model: opus-5-5
This commit is contained in:
@@ -8,6 +8,7 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"net"
|
||||
"net/http"
|
||||
"net/http/cookiejar"
|
||||
"net/url"
|
||||
@@ -41,11 +42,34 @@ func NewClient(baseURL string) *Client {
|
||||
BaseURL: baseURL,
|
||||
HTTPClient: &http.Client{ //nolint:exhaustruct // defaults fine
|
||||
Timeout: httpTimeout,
|
||||
Jar: jar,
|
||||
Jar: loopbackJar{CookieJar: jar},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
// loopbackJar also sends the server's auth cookie, which is
|
||||
// always Secure, over plain HTTP to a server on localhost, as
|
||||
// curl does. Go 1.24's cookie jar sends a Secure cookie only
|
||||
// over HTTPS.
|
||||
type loopbackJar struct {
|
||||
http.CookieJar
|
||||
}
|
||||
|
||||
// Cookies returns the cookies to send to target, treating a
|
||||
// plain-HTTP target on localhost as HTTPS.
|
||||
func (jar loopbackJar) Cookies(target *url.URL) []*http.Cookie {
|
||||
host := target.Hostname()
|
||||
loopback := host == "localhost" || net.ParseIP(host).IsLoopback()
|
||||
|
||||
if target.Scheme == "http" && loopback {
|
||||
secure := *target
|
||||
secure.Scheme = "https"
|
||||
target = &secure
|
||||
}
|
||||
|
||||
return jar.CookieJar.Cookies(target)
|
||||
}
|
||||
|
||||
// CreateSession creates a new session on the server.
|
||||
// If the server requires hashcash proof-of-work, it
|
||||
// automatically fetches the difficulty and computes a
|
||||
|
||||
Reference in New Issue
Block a user