@@ -19,8 +19,8 @@ import (
|
||||
)
|
||||
|
||||
// The tests below exercise the securecookie codecs underneath the
|
||||
// store and nothing else: Session.Get only decodes, so no server-side
|
||||
// expiry check takes part in the result. They exist because
|
||||
// store and nothing else: they decode through the store itself, so no
|
||||
// server-side expiry check takes part in the result. They exist because
|
||||
// NewCookieStore gives its codecs a 30-day max age that assigning
|
||||
// store.Options does not override, which would let the codec accept a
|
||||
// cookie weeks past the cap the cookie attribute advertises.
|
||||
@@ -75,10 +75,11 @@ func restamp(
|
||||
return base64.URLEncoding.EncodeToString(payload)
|
||||
}
|
||||
|
||||
// decodeCookie feeds value back through the store's decode path.
|
||||
// decodeCookie feeds value back through the store's decode path. It
|
||||
// asks the store rather than Session.Get, which treats a cookie that
|
||||
// does not decode as absent and so hides the codec's reason.
|
||||
func decodeCookie(
|
||||
t *testing.T,
|
||||
s *session.Session,
|
||||
value string,
|
||||
) (*sessions.Session, error) {
|
||||
t.Helper()
|
||||
@@ -94,7 +95,7 @@ func decodeCookie(
|
||||
SameSite: http.SameSiteLaxMode,
|
||||
})
|
||||
|
||||
sess, err := s.Get(req)
|
||||
sess, err := session.NewStore(testKey()).Get(req, session.SessionName)
|
||||
require.NotNil(t, sess)
|
||||
|
||||
return sess, err
|
||||
@@ -105,7 +106,7 @@ func TestCodec_AcceptsCookieInsideAbsoluteCap(t *testing.T) {
|
||||
|
||||
s := testSession(t)
|
||||
|
||||
sess, err := decodeCookie(t, s, restamp(
|
||||
sess, err := decodeCookie(t, restamp(
|
||||
t,
|
||||
issuedCookie(t, s),
|
||||
time.Now().Add(-(testAbsoluteMaxAge-time.Hour)),
|
||||
@@ -126,7 +127,7 @@ func TestCodec_RejectsCookiePastAbsoluteCap(t *testing.T) {
|
||||
|
||||
s := testSession(t)
|
||||
|
||||
sess, err := decodeCookie(t, s, restamp(
|
||||
sess, err := decodeCookie(t, restamp(
|
||||
t,
|
||||
issuedCookie(t, s),
|
||||
time.Now().Add(-(testAbsoluteMaxAge+time.Hour)),
|
||||
|
||||
@@ -224,10 +224,22 @@ func New(
|
||||
}
|
||||
|
||||
// Get retrieves a session for the request.
|
||||
//
|
||||
// A session cookie that does not decode -- one signed with an earlier
|
||||
// session key, say, because the database was made anew -- is treated
|
||||
// as absent: the caller gets a new, empty session and no error, and
|
||||
// the next save replaces the cookie.
|
||||
func (s *Session) Get(
|
||||
r *http.Request,
|
||||
) (*sessions.Session, error) {
|
||||
return s.store.Get(r, SessionName)
|
||||
sess, err := s.store.Get(r, SessionName)
|
||||
if sess == nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
// For a cookie that does not decode, gorilla/sessions returns a
|
||||
// new, empty session alongside the error that is dropped here.
|
||||
return sess, nil
|
||||
}
|
||||
|
||||
// GetKey returns the raw 32-byte authentication key used for
|
||||
|
||||
Reference in New Issue
Block a user