Let a browser with cookies from an earlier database log in (closes #359)
check / check (push) Waiting to run
check / check (push) Waiting to run
A new database brings a new session key. A browser still holding the old session cookie got a 500 on a correct login: Session.Get returned the cookie's decode error and the login handler answered it with a 500. Get now treats a cookie that does not decode as absent, and logging in replaces it. gorilla/csrf already did the same for the CSRF cookie. A start that creates webhooker.db now logs "created a new, empty database" at WARN with its path, shortly before the first-boot banner, so an unexpectedly empty DATA_DIR is noticed. The codec tests now decode through the store, since Get no longer reports the codec's reason. Model: opus-5-5
This commit was merged in pull request #362.
This commit is contained in:
@@ -224,10 +224,22 @@ func New(
|
||||
}
|
||||
|
||||
// Get retrieves a session for the request.
|
||||
//
|
||||
// A session cookie that does not decode -- one signed with an earlier
|
||||
// session key, say, because the database was made anew -- is treated
|
||||
// as absent: the caller gets a new, empty session and no error, and
|
||||
// the next save replaces the cookie.
|
||||
func (s *Session) Get(
|
||||
r *http.Request,
|
||||
) (*sessions.Session, error) {
|
||||
return s.store.Get(r, SessionName)
|
||||
sess, err := s.store.Get(r, SessionName)
|
||||
if sess == nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
// For a cookie that does not decode, gorilla/sessions returns a
|
||||
// new, empty session alongside the error that is dropped here.
|
||||
return sess, nil
|
||||
}
|
||||
|
||||
// GetKey returns the raw 32-byte authentication key used for
|
||||
|
||||
Reference in New Issue
Block a user