time.Second is 1000000000 nanoseconds. So this sets MaxAge = -1000000000, which is still negative and works to delete the cookie, but it's semantically wrong. The gorilla/sessions library expects MaxAge in seconds, and the conventional value to delete a cookie is -1.
The code works by accident (any negative value deletes the cookie), but it's confusing and could break if gorilla/sessions ever validates the range.
Suggested Fix
session.Options.MaxAge=-1
## Severity: MEDIUM
## File: `internal/service/auth/auth.go` line ~234
## Description
```go
session.Options.MaxAge = -1 * int(time.Second)
```
`time.Second` is `1000000000` nanoseconds. So this sets `MaxAge = -1000000000`, which is still negative and works to delete the cookie, but it's semantically wrong. The gorilla/sessions library expects `MaxAge` in **seconds**, and the conventional value to delete a cookie is `-1`.
The code works by accident (any negative value deletes the cookie), but it's confusing and could break if gorilla/sessions ever validates the range.
## Suggested Fix
```go
session.Options.MaxAge = -1
```
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: MEDIUM
File:
internal/service/auth/auth.goline ~234Description
time.Secondis1000000000nanoseconds. So this setsMaxAge = -1000000000, which is still negative and works to delete the cookie, but it's semantically wrong. The gorilla/sessions library expectsMaxAgein seconds, and the conventional value to delete a cookie is-1.The code works by accident (any negative value deletes the cookie), but it's confusing and could break if gorilla/sessions ever validates the range.
Suggested Fix
create a PR