From 0f9b68a0e860f64ca2cafa46418bfd38ff7dbc72 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Fri, 2 Oct 2026 14:30:51 +0200 Subject: [PATCH] Build the middleware test cookie stores with the production constructor (closes #154) The middleware tests built their cookie stores by setting store.Options by hand, which left the securecookie codecs at the library's 30-day default instead of the 7-day cap production sets, an invisible divergence that would outlive the next change to store construction. The test store constructor moves from internal/session/export_test.go into internal/session/testing.go so other packages can reach it, and the two middleware test helpers build their stores through it. No test in the repo builds a cookie store by hand any more, and no assertion changes. Model: opus-5-5 --- internal/middleware/middleware_test.go | 13 ++----------- internal/session/export_test.go | 10 ---------- internal/session/testing.go | 7 +++++++ 3 files changed, 9 insertions(+), 21 deletions(-) delete mode 100644 internal/session/export_test.go diff --git a/internal/middleware/middleware_test.go b/internal/middleware/middleware_test.go index 61dc7a2..e576659 100644 --- a/internal/middleware/middleware_test.go +++ b/internal/middleware/middleware_test.go @@ -12,7 +12,6 @@ import ( "testing" "time" - "github.com/gorilla/sessions" "github.com/stretchr/testify/assert" "github.com/stretchr/testify/require" "sneak.berlin/go/webhooker/internal/config" @@ -78,14 +77,7 @@ func newTestSessionManager( key[i] = byte(i) } - store := sessions.NewCookieStore(key) - store.Options = &sessions.Options{ - Path: "/", - MaxAge: 86400 * 7, - HttpOnly: true, - Secure: false, - SameSite: http.SameSiteLaxMode, - } + store := session.NewStore(key) var now func() time.Time @@ -931,8 +923,7 @@ func metricsAuthMiddleware( } key := make([]byte, testKeySize) - store := sessions.NewCookieStore(key) - store.Options = &sessions.Options{Path: "/", MaxAge: 86400} + store := session.NewStore(key) sessManager := session.NewForTest(store, cfg, log, key, nil) diff --git a/internal/session/export_test.go b/internal/session/export_test.go deleted file mode 100644 index 0b2ebc7..0000000 --- a/internal/session/export_test.go +++ /dev/null @@ -1,10 +0,0 @@ -package session - -import "github.com/gorilla/sessions" - -// NewStore exposes the production cookie-store constructor so tests -// exercise the store the application actually runs with, rather than a -// lookalike assembled in the test. -func NewStore(key []byte) *sessions.CookieStore { - return newStore(key) -} diff --git a/internal/session/testing.go b/internal/session/testing.go index 37666f1..18ce298 100644 --- a/internal/session/testing.go +++ b/internal/session/testing.go @@ -8,6 +8,13 @@ import ( "sneak.berlin/go/webhooker/internal/config" ) +// NewStore exposes the production cookie-store constructor so tests +// exercise the store the application actually runs with, rather than a +// lookalike assembled in the test. +func NewStore(key []byte) *sessions.CookieStore { + return newStore(key) +} + // NewForTest creates a Session with a pre-configured cookie store for use // in tests. This bypasses the fx lifecycle and database dependency, allowing // middleware and handler tests to use real session functionality. The key