Fixes the DestroySession method which was setting MaxAge = -1 * int(time.Second) (resulting in -1000000000) instead of simply -1.
The gorilla/sessions MaxAge field expects a value in seconds. The previous code multiplied by time.Second (nanoseconds), which worked by accident since any negative value deletes the cookie, but was semantically incorrect.
Changes
internal/service/auth/auth.go: Changed MaxAge = -1 * int(time.Second) to MaxAge = -1; removed unused time import
internal/service/auth/auth_test.go: Added TestDestroySessionMaxAge test
## Summary
Fixes the `DestroySession` method which was setting `MaxAge = -1 * int(time.Second)` (resulting in `-1000000000`) instead of simply `-1`.
The gorilla/sessions `MaxAge` field expects a value in **seconds**. The previous code multiplied by `time.Second` (nanoseconds), which worked by accident since any negative value deletes the cookie, but was semantically incorrect.
## Changes
- `internal/service/auth/auth.go`: Changed `MaxAge = -1 * int(time.Second)` to `MaxAge = -1`; removed unused `time` import
- `internal/service/auth/auth_test.go`: Added `TestDestroySessionMaxAge` test
(closes #39)
sneak
was assigned by clawbot2026-02-16 07:08:19 +01:00
The gorilla/sessions MaxAge field expects seconds, not nanoseconds.
Previously MaxAge was set to -1000000000 (-1 * time.Second in nanoseconds),
which worked by accident since any negative value deletes the cookie.
Changed to the conventional value of -1.
ok git.eeqj.de/sneak/upaas/internal/service/auth coverage: 70.7%
All other packages also pass (database, docker, handlers, middleware, models, app, webhook, ssh).
Lint Results ✅
No new lint issues. One pre-existing issue in internal/handlers/tail_validation_test.go (wrong package name) — not related to this change.
## Test Results ✅
All tests pass:
```
ok git.eeqj.de/sneak/upaas/internal/service/auth coverage: 70.7%
```
All other packages also pass (database, docker, handlers, middleware, models, app, webhook, ssh).
## Lint Results ✅
No new lint issues. One pre-existing issue in `internal/handlers/tail_validation_test.go` (wrong package name) — not related to this change.
sneak
merged commit 07ac71974c into main2026-02-16 07:09:26 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Fixes the
DestroySessionmethod which was settingMaxAge = -1 * int(time.Second)(resulting in-1000000000) instead of simply-1.The gorilla/sessions
MaxAgefield expects a value in seconds. The previous code multiplied bytime.Second(nanoseconds), which worked by accident since any negative value deletes the cookie, but was semantically incorrect.Changes
internal/service/auth/auth.go: ChangedMaxAge = -1 * int(time.Second)toMaxAge = -1; removed unusedtimeimportinternal/service/auth/auth_test.go: AddedTestDestroySessionMaxAgetest(closes #39)
Test Results ✅
All tests pass:
All other packages also pass (database, docker, handlers, middleware, models, app, webhook, ssh).
Lint Results ✅
No new lint issues. One pre-existing issue in
internal/handlers/tail_validation_test.go(wrong package name) — not related to this change.