Let a browser with cookies from an earlier database log in (closes #359)
check / check (push) Waiting to run
check / check (push) Waiting to run
A new database brings a new session key. A browser still holding the old session cookie got a 500 on a correct login: Session.Get returned the cookie's decode error and the login handler answered it with a 500. Get now treats a cookie that does not decode as absent, and logging in replaces it. gorilla/csrf already did the same for the CSRF cookie. A start that creates webhooker.db now logs "created a new, empty database" at WARN with its path, shortly before the first-boot banner, so an unexpectedly empty DATA_DIR is noticed. The codec tests now decode through the store, since Get no longer reports the codec's reason. Model: opus-5-5
This commit was merged in pull request #362.
This commit is contained in:
@@ -7,6 +7,7 @@ import (
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"regexp"
|
||||
"slices"
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
@@ -220,9 +221,21 @@ func (e *testEnv) csrfFrom(
|
||||
// out of the markup has to be unescaped before it is submitted.
|
||||
token := html.UnescapeString(match[1])
|
||||
|
||||
combined := make([]*http.Cookie, 0, len(cookies))
|
||||
combined = append(combined, cookies...)
|
||||
combined = append(combined, w.Result().Cookies()...)
|
||||
// A cookie the page sets replaces the one of the same name, as in
|
||||
// a browser. Sent both, the server would read the first, older one.
|
||||
set := w.Result().Cookies()
|
||||
combined := make([]*http.Cookie, 0, len(cookies)+len(set))
|
||||
|
||||
for _, c := range cookies {
|
||||
replaced := slices.ContainsFunc(set, func(n *http.Cookie) bool {
|
||||
return n.Name == c.Name
|
||||
})
|
||||
if !replaced {
|
||||
combined = append(combined, c)
|
||||
}
|
||||
}
|
||||
|
||||
combined = append(combined, set...)
|
||||
|
||||
return token, combined
|
||||
}
|
||||
@@ -614,6 +627,59 @@ func TestPagesLogin_CorrectPasswordSurvivesASpentBudget(
|
||||
)
|
||||
}
|
||||
|
||||
// TestPagesLogin_CookiesFromAnEarlierDatabase is
|
||||
// https://git.eeqj.de/sneak/webhooker/issues/359. A new database
|
||||
// brings a new session key, and the operator's browser still holds
|
||||
// the session and CSRF cookies signed with the old one. Logging in
|
||||
// must work as from a fresh browser and leave cookies the new key
|
||||
// accepts.
|
||||
func TestPagesLogin_CookiesFromAnEarlierDatabase(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const (
|
||||
username = "operator"
|
||||
password = "correct-horse-battery-staple"
|
||||
)
|
||||
|
||||
earlier := newTestEnv(t)
|
||||
earlierID, _ := earlier.seedUser(t, username, password)
|
||||
_, stale := earlier.csrfFrom(t, "/pages/login", nil)
|
||||
stale = append(stale, earlier.authCookies(t, earlierID, username)...)
|
||||
|
||||
env := newTestEnv(t)
|
||||
env.seedUser(t, username, password)
|
||||
|
||||
token, cookies := env.csrfFrom(t, "/pages/login", stale)
|
||||
|
||||
form := url.Values{}
|
||||
form.Set("csrf_token", token)
|
||||
form.Set("username", username)
|
||||
form.Set("password", password)
|
||||
|
||||
w := env.post("/pages/login", form, cookies)
|
||||
require.Equal(
|
||||
t, http.StatusSeeOther, w.Code,
|
||||
"a session cookie from another key must not fail the login",
|
||||
)
|
||||
|
||||
// The response deletes the old session cookie and then sets the
|
||||
// new one; a browser keeps the last.
|
||||
var fresh *http.Cookie
|
||||
|
||||
for _, c := range w.Result().Cookies() {
|
||||
if c.Name == session.SessionName {
|
||||
fresh = c
|
||||
}
|
||||
}
|
||||
|
||||
require.NotNil(t, fresh, "login must set a session cookie")
|
||||
assert.Equal(
|
||||
t, "/sources",
|
||||
env.get("/", []*http.Cookie{fresh}).Header().Get("Location"),
|
||||
"the new session cookie must authenticate",
|
||||
)
|
||||
}
|
||||
|
||||
// --- /user/{username} group ---
|
||||
|
||||
// TestPasswordChange_OversizeBody_RejectedAndPasswordUnchanged
|
||||
|
||||
Reference in New Issue
Block a user