Compare commits
1 Commits
issue-66-s
...
issue-90-b
| Author | SHA1 | Date | |
|---|---|---|---|
| 08c9c1a5d8 |
38
README.md
38
README.md
@@ -92,27 +92,6 @@ TTY detection, and security headers are always applied.
|
|||||||
| `METRICS_USERNAME` | Basic auth username for `/metrics` | `""` |
|
| `METRICS_USERNAME` | Basic auth username for `/metrics` | `""` |
|
||||||
| `METRICS_PASSWORD` | Basic auth password for `/metrics` | `""` |
|
| `METRICS_PASSWORD` | Basic auth password for `/metrics` | `""` |
|
||||||
| `SENTRY_DSN` | Sentry error reporting DSN | `""` |
|
| `SENTRY_DSN` | Sentry error reporting DSN | `""` |
|
||||||
| `SESSION_IDLE_TIMEOUT` | Idle session timeout (Go duration) | `24h` |
|
|
||||||
|
|
||||||
Sessions are bounded by two independent clocks, and end at whichever
|
|
||||||
one runs out first:
|
|
||||||
|
|
||||||
- **Idle expiry** (`SESSION_IDLE_TIMEOUT`, default `24h`) is a sliding
|
|
||||||
window. Every authenticated request pushes it forward, so a session
|
|
||||||
in continuous use never hits it, while an abandoned one expires a day
|
|
||||||
after its last use. Set it to `0` to disable idle expiry entirely;
|
|
||||||
the absolute cap below still applies. A set-but-unparseable value
|
|
||||||
aborts startup rather than silently falling back to the default.
|
|
||||||
- **Absolute expiry** is a fixed 7 days from login. Activity does
|
|
||||||
**not** extend it: after a week, every session ends and the user
|
|
||||||
authenticates again.
|
|
||||||
|
|
||||||
Only requests that authenticate with the session count as activity, so
|
|
||||||
an unauthenticated request carrying the cookie cannot keep a session
|
|
||||||
alive. The idle timestamp is rewritten at most once per tenth of the
|
|
||||||
idle window rather than on every request, which means a session may
|
|
||||||
expire up to 10% early relative to the user's true last request, but
|
|
||||||
never late.
|
|
||||||
|
|
||||||
On first startup, webhooker automatically generates a cryptographically
|
On first startup, webhooker automatically generates a cryptographically
|
||||||
secure session encryption key and stores it in the database. This key
|
secure session encryption key and stores it in the database. This key
|
||||||
@@ -888,9 +867,17 @@ Applied to all routes in this order:
|
|||||||
8. **Sentry** — Error reporting to Sentry (if `SENTRY_DSN` is set;
|
8. **Sentry** — Error reporting to Sentry (if `SENTRY_DSN` is set;
|
||||||
configured with `Repanic: true` so panics still reach Recoverer)
|
configured with `Repanic: true` so panics still reach Recoverer)
|
||||||
|
|
||||||
Additionally, form endpoints (`/pages`, `/sources`, `/source/*`) apply a
|
Additionally, form endpoints (`/pages`, `/user/*`, `/sources`,
|
||||||
**MaxBodySize** middleware that limits POST/PUT/PATCH request bodies to
|
`/source/*`) apply a **MaxBodySize** middleware that limits
|
||||||
1 MB using `http.MaxBytesReader`, preventing oversized form submissions.
|
POST/PUT/PATCH request bodies to 1 MB. It is registered ahead of the
|
||||||
|
CSRF middleware in every one of those route groups, because
|
||||||
|
gorilla/csrf parses the form; if the cap were installed after it, form
|
||||||
|
parsing would run under net/http's 10 MB default and the 1 MB limit
|
||||||
|
would never apply. A request that declares a `Content-Length` over the
|
||||||
|
limit is answered with `413 Request Entity Too Large` before any other
|
||||||
|
middleware or handler runs; a chunked request, or one that lies about
|
||||||
|
its length, is hard-capped by `http.MaxBytesReader` and fails
|
||||||
|
downstream at form-parse time.
|
||||||
|
|
||||||
### Authentication
|
### Authentication
|
||||||
|
|
||||||
@@ -912,7 +899,8 @@ Additionally, form endpoints (`/pages`, `/sources`, `/source/*`) apply a
|
|||||||
- Production security headers on all responses: HSTS, X-Content-Type-Options
|
- Production security headers on all responses: HSTS, X-Content-Type-Options
|
||||||
(`nosniff`), X-Frame-Options (`DENY`), Content-Security-Policy, Referrer-Policy,
|
(`nosniff`), X-Frame-Options (`DENY`), Content-Security-Policy, Referrer-Policy,
|
||||||
and Permissions-Policy
|
and Permissions-Policy
|
||||||
- Request body size limits (1 MB) on all form POST endpoints
|
- Request body size limits (1 MB) on all form POST endpoints, enforced
|
||||||
|
by middleware that runs before CSRF parses the form
|
||||||
- **CSRF protection** via [gorilla/csrf](https://github.com/gorilla/csrf)
|
- **CSRF protection** via [gorilla/csrf](https://github.com/gorilla/csrf)
|
||||||
on all state-changing forms (cookie-based double-submit tokens with
|
on all state-changing forms (cookie-based double-submit tokens with
|
||||||
HMAC authentication). Applied to `/pages`, `/sources`, `/source`, and
|
HMAC authentication). Applied to `/pages`, `/sources`, `/source`, and
|
||||||
|
|||||||
13
TODO.md
13
TODO.md
@@ -28,10 +28,13 @@ databases currently grow without bound.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-08-09 Inactivity-based session timeout: sliding idle expiry
|
- 2026-08-09 Enforce the request body size limit before the CSRF
|
||||||
(`SESSION_IDLE_TIMEOUT`, default `24h`) refreshed on authenticated
|
middleware parses the form (#90): `MaxBodySize` is now registered
|
||||||
requests, with the 7-day absolute cap kept as an independent
|
ahead of `CSRF()` in every form route group, the `/user/{username}`
|
||||||
backstop that activity never extends (#66)
|
group gained the cap it never had (which is where `POST /password`
|
||||||
|
lives), the middleware rejects a declared-oversize body with a real
|
||||||
|
413 up front, and the redundant handler-local
|
||||||
|
`http.MaxBytesReader` calls were removed
|
||||||
- 2026-08-07 Update golangci-lint to v2.12.2 (Docker image digest in
|
- 2026-08-07 Update golangci-lint to v2.12.2 (Docker image digest in
|
||||||
`Dockerfile`, release-archive sha256 pins in `script/bootstrap`),
|
`Dockerfile`, release-archive sha256 pins in `script/bootstrap`),
|
||||||
adopt the canonical `.golangci.yml` (v2 `linters.settings` layout so
|
adopt the canonical `.golangci.yml` (v2 `linters.settings` layout so
|
||||||
@@ -75,7 +78,7 @@ databases currently grow without bound.
|
|||||||
- event redelivery endpoint
|
- event redelivery endpoint
|
||||||
- OpenAPI specification
|
- OpenAPI specification
|
||||||
- Analytics dashboard: success rates, response times, volume
|
- Analytics dashboard: success rates, response times, volume
|
||||||
- A remember-me option at login
|
- Session expiration tuning and a remember-me option
|
||||||
- Password change and reset flow
|
- Password change and reset flow
|
||||||
- Later, nice to have
|
- Later, nice to have
|
||||||
- email delivery target type
|
- email delivery target type
|
||||||
|
|||||||
@@ -31,10 +31,6 @@ const (
|
|||||||
// defaultRetentionSweepInterval is how often the retention
|
// defaultRetentionSweepInterval is how often the retention
|
||||||
// reaper deletes events older than each webhook's RetentionDays.
|
// reaper deletes events older than each webhook's RetentionDays.
|
||||||
defaultRetentionSweepInterval = time.Hour
|
defaultRetentionSweepInterval = time.Hour
|
||||||
|
|
||||||
// defaultSessionIdleTimeout is how long a session may go without
|
|
||||||
// authenticated activity before it expires.
|
|
||||||
defaultSessionIdleTimeout = 24 * time.Hour
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// ErrInvalidEnvironment is returned when WEBHOOKER_ENVIRONMENT
|
// ErrInvalidEnvironment is returned when WEBHOOKER_ENVIRONMENT
|
||||||
@@ -64,10 +60,6 @@ type Config struct {
|
|||||||
// RetentionSweepInterval is how often the retention reaper runs.
|
// RetentionSweepInterval is how often the retention reaper runs.
|
||||||
RetentionSweepInterval time.Duration
|
RetentionSweepInterval time.Duration
|
||||||
|
|
||||||
// SessionIdleTimeout is the sliding inactivity window after
|
|
||||||
// which a session expires. Non-positive disables idle expiry.
|
|
||||||
SessionIdleTimeout time.Duration
|
|
||||||
|
|
||||||
params *ConfigParams
|
params *ConfigParams
|
||||||
log *slog.Logger
|
log *slog.Logger
|
||||||
}
|
}
|
||||||
@@ -170,15 +162,6 @@ func New(lc fx.Lifecycle, params ConfigParams) (*Config, error) {
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// Same fail-loud treatment for the session idle timeout.
|
|
||||||
sessionIdleTimeout, err := envDuration(
|
|
||||||
"SESSION_IDLE_TIMEOUT",
|
|
||||||
defaultSessionIdleTimeout,
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
// Load configuration values from environment variables
|
// Load configuration values from environment variables
|
||||||
s := &Config{
|
s := &Config{
|
||||||
DataDir: envString("DATA_DIR"),
|
DataDir: envString("DATA_DIR"),
|
||||||
@@ -190,7 +173,6 @@ func New(lc fx.Lifecycle, params ConfigParams) (*Config, error) {
|
|||||||
Port: envInt("PORT", defaultPort),
|
Port: envInt("PORT", defaultPort),
|
||||||
SentryDSN: envString("SENTRY_DSN"),
|
SentryDSN: envString("SENTRY_DSN"),
|
||||||
RetentionSweepInterval: retentionSweepInterval,
|
RetentionSweepInterval: retentionSweepInterval,
|
||||||
SessionIdleTimeout: sessionIdleTimeout,
|
|
||||||
log: log,
|
log: log,
|
||||||
params: ¶ms,
|
params: ¶ms,
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -163,7 +163,7 @@ func TestRetentionSweepInterval(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if tt.expectError {
|
if tt.expectError {
|
||||||
expectStartupError(t)
|
testRetentionSweepIntervalError(t)
|
||||||
} else {
|
} else {
|
||||||
testRetentionSweepIntervalSuccess(t, tt.expected)
|
testRetentionSweepIntervalSuccess(t, tt.expected)
|
||||||
}
|
}
|
||||||
@@ -171,9 +171,7 @@ func TestRetentionSweepInterval(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// expectStartupError asserts that fx refuses to build the app,
|
func testRetentionSweepIntervalError(t *testing.T) {
|
||||||
// which is what a set-but-unparseable duration must cause.
|
|
||||||
func expectStartupError(t *testing.T) {
|
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
var cfg *config.Config
|
var cfg *config.Config
|
||||||
@@ -217,82 +215,6 @@ func testRetentionSweepIntervalSuccess(
|
|||||||
assert.Equal(t, expected, cfg.RetentionSweepInterval)
|
assert.Equal(t, expected, cfg.RetentionSweepInterval)
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestSessionIdleTimeout(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
set bool
|
|
||||||
value string
|
|
||||||
expectError bool
|
|
||||||
expected time.Duration
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "unset uses default",
|
|
||||||
set: false,
|
|
||||||
expected: 24 * time.Hour,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "valid value is parsed",
|
|
||||||
set: true,
|
|
||||||
value: "30m",
|
|
||||||
expected: 30 * time.Minute,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "unparseable value fails startup",
|
|
||||||
set: true,
|
|
||||||
value: "not-a-duration",
|
|
||||||
expectError: true,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
// Cannot use t.Parallel() here because t.Setenv
|
|
||||||
// is incompatible with parallel subtests.
|
|
||||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
|
||||||
|
|
||||||
if tt.set {
|
|
||||||
t.Setenv("SESSION_IDLE_TIMEOUT", tt.value)
|
|
||||||
} else {
|
|
||||||
require.NoError(t, os.Unsetenv(
|
|
||||||
"SESSION_IDLE_TIMEOUT",
|
|
||||||
))
|
|
||||||
}
|
|
||||||
|
|
||||||
if tt.expectError {
|
|
||||||
expectStartupError(t)
|
|
||||||
} else {
|
|
||||||
testSessionIdleTimeoutSuccess(t, tt.expected)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func testSessionIdleTimeoutSuccess(
|
|
||||||
t *testing.T,
|
|
||||||
expected time.Duration,
|
|
||||||
) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var cfg *config.Config
|
|
||||||
|
|
||||||
app := fxtest.New(
|
|
||||||
t,
|
|
||||||
fx.Provide(
|
|
||||||
globals.New,
|
|
||||||
logger.New,
|
|
||||||
config.New,
|
|
||||||
),
|
|
||||||
fx.Populate(&cfg),
|
|
||||||
)
|
|
||||||
require.NoError(t, app.Err())
|
|
||||||
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
defer app.RequireStop()
|
|
||||||
|
|
||||||
assert.Equal(t, expected, cfg.SessionIdleTimeout)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestDefaultDataDir(t *testing.T) {
|
func TestDefaultDataDir(t *testing.T) {
|
||||||
for _, env := range []string{"", "dev", "prod"} {
|
for _, env := range []string{"", "dev", "prod"} {
|
||||||
name := env
|
name := env
|
||||||
|
|||||||
@@ -29,10 +29,8 @@ func (h *Handlers) HandleLoginPage() http.HandlerFunc {
|
|||||||
// HandleLoginSubmit handles the login form submission (POST)
|
// HandleLoginSubmit handles the login form submission (POST)
|
||||||
func (h *Handlers) HandleLoginSubmit() http.HandlerFunc {
|
func (h *Handlers) HandleLoginSubmit() http.HandlerFunc {
|
||||||
return func(w http.ResponseWriter, r *http.Request) {
|
return func(w http.ResponseWriter, r *http.Request) {
|
||||||
// Limit request body to prevent memory exhaustion
|
// The body size cap is enforced by the MaxBodySize
|
||||||
r.Body = http.MaxBytesReader(w, r.Body, 1<<maxBodyShift)
|
// middleware, which runs before CSRF parses the form.
|
||||||
|
|
||||||
// Parse form data
|
|
||||||
err := r.ParseForm()
|
err := r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.log.Error("failed to parse form", "error", err)
|
h.log.Error("failed to parse form", "error", err)
|
||||||
|
|||||||
@@ -31,9 +31,8 @@ func (h *Handlers) HandlePasswordChange() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// Limit request body to prevent memory exhaustion.
|
// The body size cap is enforced by the MaxBodySize
|
||||||
r.Body = http.MaxBytesReader(w, r.Body, 1<<maxBodyShift)
|
// middleware, which runs before CSRF parses the form.
|
||||||
|
|
||||||
err := r.ParseForm()
|
err := r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.log.Error("failed to parse form", "error", err)
|
h.log.Error("failed to parse form", "error", err)
|
||||||
|
|||||||
@@ -127,10 +127,8 @@ func (h *Handlers) HandleSourceCreateSubmit() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
r.Body = http.MaxBytesReader(
|
// The body size cap is enforced by the MaxBodySize
|
||||||
w, r.Body, 1<<maxBodyShift,
|
// middleware, which runs before CSRF parses the form.
|
||||||
)
|
|
||||||
|
|
||||||
err := r.ParseForm()
|
err := r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -386,10 +384,8 @@ func (h *Handlers) HandleSourceEditSubmit() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
r.Body = http.MaxBytesReader(
|
// The body size cap is enforced by the MaxBodySize
|
||||||
w, r.Body, 1<<maxBodyShift,
|
// middleware, which runs before CSRF parses the form.
|
||||||
)
|
|
||||||
|
|
||||||
err = r.ParseForm()
|
err = r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -409,10 +405,8 @@ func (h *Handlers) applyWebhookEdit(
|
|||||||
r *http.Request,
|
r *http.Request,
|
||||||
webhook *database.Webhook,
|
webhook *database.Webhook,
|
||||||
) {
|
) {
|
||||||
r.Body = http.MaxBytesReader(
|
// The body size cap is enforced by the MaxBodySize middleware,
|
||||||
w, r.Body, 1<<maxBodyShift,
|
// which runs before CSRF parses the form.
|
||||||
)
|
|
||||||
|
|
||||||
name := r.FormValue("name")
|
name := r.FormValue("name")
|
||||||
if name == "" {
|
if name == "" {
|
||||||
data := map[string]any{
|
data := map[string]any{
|
||||||
@@ -725,10 +719,8 @@ func (h *Handlers) HandleEntrypointCreate() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
r.Body = http.MaxBytesReader(
|
// The body size cap is enforced by the MaxBodySize
|
||||||
w, r.Body, 1<<maxBodyShift,
|
// middleware, which runs before CSRF parses the form.
|
||||||
)
|
|
||||||
|
|
||||||
err = r.ParseForm()
|
err = r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -785,10 +777,8 @@ func (h *Handlers) HandleTargetCreate() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
r.Body = http.MaxBytesReader(
|
// The body size cap is enforced by the MaxBodySize
|
||||||
w, r.Body, 1<<maxBodyShift,
|
// middleware, which runs before CSRF parses the form.
|
||||||
)
|
|
||||||
|
|
||||||
err = r.ParseForm()
|
err = r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -808,10 +798,8 @@ func (h *Handlers) processTargetCreate(
|
|||||||
r *http.Request,
|
r *http.Request,
|
||||||
webhook database.Webhook,
|
webhook database.Webhook,
|
||||||
) {
|
) {
|
||||||
r.Body = http.MaxBytesReader(
|
// The body size cap is enforced by the MaxBodySize middleware,
|
||||||
w, r.Body, 1<<maxBodyShift,
|
// which runs before CSRF parses the form.
|
||||||
)
|
|
||||||
|
|
||||||
name := r.FormValue("name")
|
name := r.FormValue("name")
|
||||||
targetType := database.TargetType(r.FormValue("type"))
|
targetType := database.TargetType(r.FormValue("type"))
|
||||||
targetURL := r.FormValue("url")
|
targetURL := r.FormValue("url")
|
||||||
|
|||||||
@@ -186,10 +186,6 @@ func (s *Middleware) RequireAuth() func(http.Handler) http.Handler {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// IsAuthenticated also enforces both session expiry
|
|
||||||
// deadlines, so an idle-expired or absolutely-expired
|
|
||||||
// session lands here and is sent back to the login
|
|
||||||
// page.
|
|
||||||
if !s.session.IsAuthenticated(sess) {
|
if !s.session.IsAuthenticated(sess) {
|
||||||
s.log.Debug(
|
s.log.Debug(
|
||||||
"auth middleware: unauthenticated request",
|
"auth middleware: unauthenticated request",
|
||||||
@@ -203,26 +199,6 @@ func (s *Middleware) RequireAuth() func(http.Handler) http.Handler {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// This request authenticated with the session, so it
|
|
||||||
// counts as activity: push the idle deadline forward.
|
|
||||||
// This is the only place sessions are refreshed, which
|
|
||||||
// is what keeps an unauthenticated request from
|
|
||||||
// extending someone else's session. Touch advances the
|
|
||||||
// idle clock only -- the absolute cap is untouched --
|
|
||||||
// and reports false when nothing changed, so most
|
|
||||||
// requests do not re-issue the cookie. Save before the
|
|
||||||
// handler runs, while the headers are still ours to
|
|
||||||
// write.
|
|
||||||
if s.session.Touch(sess) {
|
|
||||||
err = s.session.Save(r, w, sess)
|
|
||||||
if err != nil {
|
|
||||||
s.log.Error(
|
|
||||||
"auth middleware: failed to refresh session",
|
|
||||||
"error", err,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
next.ServeHTTP(w, r)
|
next.ServeHTTP(w, r)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -309,10 +285,36 @@ func (s *Middleware) NoCache() func(http.Handler) http.Handler {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// MaxBodySize returns middleware that limits the request body size
|
// bodyLimitedMethod reports whether the request method carries a
|
||||||
// for POST requests. If the body exceeds the given limit in
|
// body that the MaxBodySize middleware should cap.
|
||||||
// bytes, the server returns 413 Request Entity Too Large. This
|
func bodyLimitedMethod(method string) bool {
|
||||||
// prevents clients from sending arbitrarily large form bodies.
|
return method == http.MethodPost ||
|
||||||
|
method == http.MethodPut ||
|
||||||
|
method == http.MethodPatch
|
||||||
|
}
|
||||||
|
|
||||||
|
// MaxBodySize returns middleware that limits the size of
|
||||||
|
// POST/PUT/PATCH request bodies to maxBytes. It must be registered
|
||||||
|
// before any middleware that parses the body — notably CSRF, which
|
||||||
|
// calls r.PostFormValue — so that form parsing happens under this
|
||||||
|
// cap rather than net/http's 10 MB default.
|
||||||
|
//
|
||||||
|
// Two enforcement paths exist, because http.MaxBytesReader alone
|
||||||
|
// cannot produce a 413: it reports the overflow as an error from
|
||||||
|
// Read, by which point the body parser downstream has already
|
||||||
|
// converted that error into its own response.
|
||||||
|
//
|
||||||
|
// - Declared oversize: the request announces a Content-Length
|
||||||
|
// greater than maxBytes. The middleware answers 413 Request
|
||||||
|
// Entity Too Large immediately and does not call the next
|
||||||
|
// handler, so neither CSRF nor the endpoint handler runs.
|
||||||
|
// - Undeclared oversize: the request is chunked (Content-Length
|
||||||
|
// of -1) or lies about its Content-Length. There is nothing to
|
||||||
|
// check up front, so http.MaxBytesReader hard-caps the body at
|
||||||
|
// maxBytes and the request fails downstream — the form parse
|
||||||
|
// errors out and CSRF rejects it with 403. The response is less
|
||||||
|
// precise than a 413, but the body is still never buffered
|
||||||
|
// beyond the cap, which is the property that matters.
|
||||||
func (s *Middleware) MaxBodySize(
|
func (s *Middleware) MaxBodySize(
|
||||||
maxBytes int64,
|
maxBytes int64,
|
||||||
) func(http.Handler) http.Handler {
|
) func(http.Handler) http.Handler {
|
||||||
@@ -321,14 +323,31 @@ func (s *Middleware) MaxBodySize(
|
|||||||
w http.ResponseWriter,
|
w http.ResponseWriter,
|
||||||
r *http.Request,
|
r *http.Request,
|
||||||
) {
|
) {
|
||||||
if r.Method == http.MethodPost ||
|
if !bodyLimitedMethod(r.Method) {
|
||||||
r.Method == http.MethodPut ||
|
next.ServeHTTP(w, r)
|
||||||
r.Method == http.MethodPatch {
|
|
||||||
r.Body = http.MaxBytesReader(
|
return
|
||||||
w, r.Body, maxBytes,
|
|
||||||
)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if r.ContentLength > maxBytes {
|
||||||
|
s.log.Warn(
|
||||||
|
"request body exceeds limit",
|
||||||
|
"method", r.Method,
|
||||||
|
"path", r.URL.Path,
|
||||||
|
"content_length", r.ContentLength,
|
||||||
|
"limit", maxBytes,
|
||||||
|
)
|
||||||
|
http.Error(
|
||||||
|
w,
|
||||||
|
"Request Entity Too Large",
|
||||||
|
http.StatusRequestEntityTooLarge,
|
||||||
|
)
|
||||||
|
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
r.Body = http.MaxBytesReader(w, r.Body, maxBytes)
|
||||||
|
|
||||||
next.ServeHTTP(w, r)
|
next.ServeHTTP(w, r)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,12 +3,13 @@ package middleware_test
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"encoding/base64"
|
"encoding/base64"
|
||||||
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"os"
|
"os"
|
||||||
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/gorilla/sessions"
|
"github.com/gorilla/sessions"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
@@ -29,22 +30,6 @@ func testMiddleware(
|
|||||||
) (*middleware.Middleware, *session.Session) {
|
) (*middleware.Middleware, *session.Session) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
m, s, _ := testMiddlewareWithSessionClock(t, env, 0, nil)
|
|
||||||
|
|
||||||
return m, s
|
|
||||||
}
|
|
||||||
|
|
||||||
// testMiddlewareWithSessionClock is testMiddleware with a
|
|
||||||
// configurable session idle timeout and a manually advanced clock,
|
|
||||||
// for the session-expiry tests. A nil clock uses the real one.
|
|
||||||
func testMiddlewareWithSessionClock(
|
|
||||||
t *testing.T,
|
|
||||||
env string,
|
|
||||||
idleTimeout time.Duration,
|
|
||||||
clock *fakeClock,
|
|
||||||
) (*middleware.Middleware, *session.Session, *fakeClock) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
log := slog.New(slog.NewTextHandler(
|
log := slog.New(slog.NewTextHandler(
|
||||||
os.Stderr,
|
os.Stderr,
|
||||||
&slog.HandlerOptions{Level: slog.LevelDebug},
|
&slog.HandlerOptions{Level: slog.LevelDebug},
|
||||||
@@ -52,7 +37,6 @@ func testMiddlewareWithSessionClock(
|
|||||||
|
|
||||||
cfg := &config.Config{
|
cfg := &config.Config{
|
||||||
Environment: env,
|
Environment: env,
|
||||||
SessionIdleTimeout: idleTimeout,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Create a real session manager with a known key
|
// Create a real session manager with a known key
|
||||||
@@ -71,40 +55,11 @@ func testMiddlewareWithSessionClock(
|
|||||||
SameSite: http.SameSiteLaxMode,
|
SameSite: http.SameSiteLaxMode,
|
||||||
}
|
}
|
||||||
|
|
||||||
var now func() time.Time
|
sessManager := session.NewForTest(store, cfg, log, key)
|
||||||
|
|
||||||
if clock != nil {
|
|
||||||
now = clock.Now
|
|
||||||
}
|
|
||||||
|
|
||||||
sessManager := session.NewForTest(store, cfg, log, key, now)
|
|
||||||
|
|
||||||
m := middleware.NewForTest(log, cfg, sessManager)
|
m := middleware.NewForTest(log, cfg, sessManager)
|
||||||
|
|
||||||
return m, sessManager, clock
|
return m, sessManager
|
||||||
}
|
|
||||||
|
|
||||||
// fakeClock is a manually advanced clock, so session expiry can be
|
|
||||||
// tested without sleeping.
|
|
||||||
type fakeClock struct {
|
|
||||||
t time.Time
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *fakeClock) Now() time.Time {
|
|
||||||
return c.t
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *fakeClock) Advance(d time.Duration) {
|
|
||||||
c.t = c.t.Add(d)
|
|
||||||
}
|
|
||||||
|
|
||||||
// newFakeClock returns a clock started at a fixed instant.
|
|
||||||
func newFakeClock() *fakeClock {
|
|
||||||
return &fakeClock{
|
|
||||||
t: time.Date(
|
|
||||||
2026, time.January, 2, 3, 4, 5, 0, time.UTC,
|
|
||||||
),
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- Logging Middleware Tests ---
|
// --- Logging Middleware Tests ---
|
||||||
@@ -434,181 +389,6 @@ func TestRequireAuth_UnauthenticatedSession_RedirectsToLogin(
|
|||||||
assert.Equal(t, "/pages/login", w.Header().Get("Location"))
|
assert.Equal(t, "/pages/login", w.Header().Get("Location"))
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- RequireAuth Session Expiry Tests ---
|
|
||||||
|
|
||||||
// loginCookies authenticates a new session and returns the cookies
|
|
||||||
// a browser would then send back.
|
|
||||||
func loginCookies(
|
|
||||||
t *testing.T,
|
|
||||||
sessManager *session.Session,
|
|
||||||
) []*http.Cookie {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, "/login", nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
sess, err := sessManager.Get(req)
|
|
||||||
require.NoError(t, err)
|
|
||||||
sessManager.SetUser(sess, "user-123", "testuser")
|
|
||||||
require.NoError(t, sessManager.Save(req, w, sess))
|
|
||||||
|
|
||||||
cookies := w.Result().Cookies()
|
|
||||||
require.NotEmpty(t, cookies, "session cookie should be set")
|
|
||||||
|
|
||||||
return cookies
|
|
||||||
}
|
|
||||||
|
|
||||||
// runAuthed sends a request carrying cookies through RequireAuth
|
|
||||||
// and reports whether the protected handler ran, plus the response.
|
|
||||||
func runAuthed(
|
|
||||||
t *testing.T,
|
|
||||||
m *middleware.Middleware,
|
|
||||||
cookies []*http.Cookie,
|
|
||||||
) (bool, *httptest.ResponseRecorder) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var called bool
|
|
||||||
|
|
||||||
handler := m.RequireAuth()(http.HandlerFunc(
|
|
||||||
func(_ http.ResponseWriter, _ *http.Request) {
|
|
||||||
called = true
|
|
||||||
},
|
|
||||||
))
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(),
|
|
||||||
http.MethodGet, "/dashboard", nil,
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, c := range cookies {
|
|
||||||
req.AddCookie(c)
|
|
||||||
}
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
handler.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return called, w
|
|
||||||
}
|
|
||||||
|
|
||||||
// sessionCookies filters a response's cookies down to the session
|
|
||||||
// cookie, so tests can tell whether the session was re-issued.
|
|
||||||
func sessionCookies(
|
|
||||||
w *httptest.ResponseRecorder,
|
|
||||||
) []*http.Cookie {
|
|
||||||
var out []*http.Cookie
|
|
||||||
|
|
||||||
for _, c := range w.Result().Cookies() {
|
|
||||||
if c.Name == session.SessionName {
|
|
||||||
out = append(out, c)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRequireAuth_IdleExpiredSession_RedirectsToLogin(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
idle := time.Hour
|
|
||||||
|
|
||||||
m, sessManager, clock := testMiddlewareWithSessionClock(
|
|
||||||
t, config.EnvironmentDev, idle, newFakeClock(),
|
|
||||||
)
|
|
||||||
|
|
||||||
cookies := loginCookies(t, sessManager)
|
|
||||||
|
|
||||||
clock.Advance(idle)
|
|
||||||
|
|
||||||
called, w := runAuthed(t, m, cookies)
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, called,
|
|
||||||
"handler should not run for an idle-expired session",
|
|
||||||
)
|
|
||||||
assert.Equal(t, http.StatusSeeOther, w.Code)
|
|
||||||
assert.Equal(t, "/pages/login", w.Header().Get("Location"))
|
|
||||||
assert.Empty(
|
|
||||||
t, sessionCookies(w),
|
|
||||||
"an expired session must not be refreshed",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRequireAuth_RefreshesIdleDeadlineOnActivity(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
idle := time.Hour
|
|
||||||
|
|
||||||
m, sessManager, clock := testMiddlewareWithSessionClock(
|
|
||||||
t, config.EnvironmentDev, idle, newFakeClock(),
|
|
||||||
)
|
|
||||||
|
|
||||||
cookies := loginCookies(t, sessManager)
|
|
||||||
|
|
||||||
// Activity halfway through the idle window.
|
|
||||||
clock.Advance(idle / 2)
|
|
||||||
|
|
||||||
called, w := runAuthed(t, m, cookies)
|
|
||||||
require.True(t, called, "handler should run while valid")
|
|
||||||
|
|
||||||
refreshed := sessionCookies(w)
|
|
||||||
require.NotEmpty(
|
|
||||||
t, refreshed,
|
|
||||||
"activity should re-issue the session cookie",
|
|
||||||
)
|
|
||||||
|
|
||||||
// Past the original deadline. The refreshed cookie is still
|
|
||||||
// good; the original one is not.
|
|
||||||
clock.Advance(idle - time.Second)
|
|
||||||
|
|
||||||
calledRefreshed, _ := runAuthed(t, m, refreshed)
|
|
||||||
assert.True(
|
|
||||||
t, calledRefreshed,
|
|
||||||
"refreshed session should outlive the original deadline",
|
|
||||||
)
|
|
||||||
|
|
||||||
calledStale, staleW := runAuthed(t, m, cookies)
|
|
||||||
assert.False(
|
|
||||||
t, calledStale,
|
|
||||||
"the pre-refresh cookie carries the old idle deadline",
|
|
||||||
)
|
|
||||||
assert.Equal(t, http.StatusSeeOther, staleW.Code)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRequireAuth_UnauthenticatedRequestDoesNotRefresh(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
m, sessManager, _ := testMiddlewareWithSessionClock(
|
|
||||||
t, config.EnvironmentDev, time.Hour, newFakeClock(),
|
|
||||||
)
|
|
||||||
|
|
||||||
// A session cookie that exists but was never authenticated.
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, "/setup", nil)
|
|
||||||
setupW := httptest.NewRecorder()
|
|
||||||
|
|
||||||
sess, err := sessManager.Get(req)
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.NoError(t, sessManager.Save(req, setupW, sess))
|
|
||||||
|
|
||||||
cookies := setupW.Result().Cookies()
|
|
||||||
require.NotEmpty(t, cookies)
|
|
||||||
|
|
||||||
called, w := runAuthed(t, m, cookies)
|
|
||||||
|
|
||||||
assert.False(t, called)
|
|
||||||
assert.Empty(
|
|
||||||
t, sessionCookies(w),
|
|
||||||
"an unauthenticated request must not stamp the session",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// --- NoCache Middleware Tests ---
|
// --- NoCache Middleware Tests ---
|
||||||
|
|
||||||
func TestNoCache_SetsHeaders(t *testing.T) {
|
func TestNoCache_SetsHeaders(t *testing.T) {
|
||||||
@@ -648,6 +428,153 @@ func TestNoCache_SetsHeaders(t *testing.T) {
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// --- MaxBodySize Middleware Tests ---
|
||||||
|
|
||||||
|
const testBodyLimit int64 = 64
|
||||||
|
|
||||||
|
// maxBodySizeHandler wraps a sentinel handler in MaxBodySize with
|
||||||
|
// testBodyLimit. The sentinel records whether it ran and how much of
|
||||||
|
// the body it managed to read, so tests can distinguish "never
|
||||||
|
// reached" from "reached but truncated".
|
||||||
|
type maxBodySizeResult struct {
|
||||||
|
called bool
|
||||||
|
read int
|
||||||
|
readErr error
|
||||||
|
response *httptest.ResponseRecorder
|
||||||
|
}
|
||||||
|
|
||||||
|
func runMaxBodySize(
|
||||||
|
t *testing.T,
|
||||||
|
req *http.Request,
|
||||||
|
) *maxBodySizeResult {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
m, _ := testMiddleware(t, config.EnvironmentDev)
|
||||||
|
res := &maxBodySizeResult{response: httptest.NewRecorder()}
|
||||||
|
|
||||||
|
handler := m.MaxBodySize(testBodyLimit)(http.HandlerFunc(
|
||||||
|
func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
res.called = true
|
||||||
|
|
||||||
|
body, err := io.ReadAll(r.Body)
|
||||||
|
res.read = len(body)
|
||||||
|
res.readErr = err
|
||||||
|
|
||||||
|
w.WriteHeader(http.StatusOK)
|
||||||
|
},
|
||||||
|
))
|
||||||
|
|
||||||
|
handler.ServeHTTP(res.response, req)
|
||||||
|
|
||||||
|
return res
|
||||||
|
}
|
||||||
|
|
||||||
|
// postWithBody builds a POST request whose Content-Length is
|
||||||
|
// accurate for the given payload size.
|
||||||
|
func postWithBody(size int) *http.Request {
|
||||||
|
req := httptest.NewRequestWithContext(
|
||||||
|
context.Background(),
|
||||||
|
http.MethodPost, "/pages/login",
|
||||||
|
strings.NewReader(strings.Repeat("a", size)),
|
||||||
|
)
|
||||||
|
req.Header.Set(
|
||||||
|
"Content-Type", "application/x-www-form-urlencoded",
|
||||||
|
)
|
||||||
|
|
||||||
|
return req
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMaxBodySize_DeclaredOversize_413AndHandlerNotReached(
|
||||||
|
t *testing.T,
|
||||||
|
) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
res := runMaxBodySize(t, postWithBody(int(testBodyLimit)+1))
|
||||||
|
|
||||||
|
assert.False(
|
||||||
|
t, res.called,
|
||||||
|
"handler must not be reached for an oversized body",
|
||||||
|
)
|
||||||
|
assert.Equal(
|
||||||
|
t, http.StatusRequestEntityTooLarge, res.response.Code,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMaxBodySize_AtLimit_PassesThrough(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
res := runMaxBodySize(t, postWithBody(int(testBodyLimit)))
|
||||||
|
|
||||||
|
assert.True(
|
||||||
|
t, res.called,
|
||||||
|
"handler should be reached for a body at the limit",
|
||||||
|
)
|
||||||
|
require.NoError(t, res.readErr)
|
||||||
|
assert.Equal(t, int(testBodyLimit), res.read)
|
||||||
|
assert.Equal(t, http.StatusOK, res.response.Code)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMaxBodySize_UnderLimit_PassesThrough(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
res := runMaxBodySize(t, postWithBody(1))
|
||||||
|
|
||||||
|
assert.True(t, res.called)
|
||||||
|
require.NoError(t, res.readErr)
|
||||||
|
assert.Equal(t, 1, res.read)
|
||||||
|
assert.Equal(t, http.StatusOK, res.response.Code)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMaxBodySize_GetWithOversizeBody_NotCapped(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
req := httptest.NewRequestWithContext(
|
||||||
|
context.Background(),
|
||||||
|
http.MethodGet, "/pages/login",
|
||||||
|
strings.NewReader(
|
||||||
|
strings.Repeat("a", int(testBodyLimit)+1),
|
||||||
|
),
|
||||||
|
)
|
||||||
|
|
||||||
|
res := runMaxBodySize(t, req)
|
||||||
|
|
||||||
|
assert.True(
|
||||||
|
t, res.called,
|
||||||
|
"GET requests are not subject to the POST body cap",
|
||||||
|
)
|
||||||
|
require.NoError(t, res.readErr)
|
||||||
|
assert.Equal(t, int(testBodyLimit)+1, res.read)
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestMaxBodySize_UndeclaredOversize_TruncatedAtCap covers the
|
||||||
|
// chunked / lying-Content-Length case: there is nothing to check up
|
||||||
|
// front, so the request reaches the handler but MaxBytesReader
|
||||||
|
// hard-caps the body and the read fails at the limit.
|
||||||
|
func TestMaxBodySize_UndeclaredOversize_TruncatedAtCap(
|
||||||
|
t *testing.T,
|
||||||
|
) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
req := postWithBody(int(testBodyLimit) + 1)
|
||||||
|
// Simulate a chunked request: no declared length.
|
||||||
|
req.ContentLength = -1
|
||||||
|
|
||||||
|
res := runMaxBodySize(t, req)
|
||||||
|
|
||||||
|
assert.True(
|
||||||
|
t, res.called,
|
||||||
|
"an undeclared oversize body cannot be rejected up front",
|
||||||
|
)
|
||||||
|
require.Error(
|
||||||
|
t, res.readErr,
|
||||||
|
"reading past the cap must fail",
|
||||||
|
)
|
||||||
|
assert.Equal(
|
||||||
|
t, int(testBodyLimit), res.read,
|
||||||
|
"the handler must not see more than the cap",
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
// --- Helper Tests ---
|
// --- Helper Tests ---
|
||||||
|
|
||||||
func TestIpFromHostPort(t *testing.T) {
|
func TestIpFromHostPort(t *testing.T) {
|
||||||
@@ -701,7 +628,7 @@ func metricsAuthMiddleware(
|
|||||||
store := sessions.NewCookieStore(key)
|
store := sessions.NewCookieStore(key)
|
||||||
store.Options = &sessions.Options{Path: "/", MaxAge: 86400}
|
store.Options = &sessions.Options{Path: "/", MaxAge: 86400}
|
||||||
|
|
||||||
sessManager := session.NewForTest(store, cfg, log, key, nil)
|
sessManager := session.NewForTest(store, cfg, log, key)
|
||||||
|
|
||||||
return middleware.NewForTest(log, cfg, sessManager)
|
return middleware.NewForTest(log, cfg, sessManager)
|
||||||
}
|
}
|
||||||
|
|||||||
36
internal/server/export_test.go
Normal file
36
internal/server/export_test.go
Normal file
@@ -0,0 +1,36 @@
|
|||||||
|
package server
|
||||||
|
|
||||||
|
import (
|
||||||
|
"log/slog"
|
||||||
|
"net/http"
|
||||||
|
|
||||||
|
"sneak.berlin/go/webhooker/internal/config"
|
||||||
|
"sneak.berlin/go/webhooker/internal/handlers"
|
||||||
|
"sneak.berlin/go/webhooker/internal/middleware"
|
||||||
|
)
|
||||||
|
|
||||||
|
// MaxFormBodySizeForTest exposes the form body cap so tests can
|
||||||
|
// build requests that sit exactly at, below, and above it.
|
||||||
|
const MaxFormBodySizeForTest = maxFormBodySize
|
||||||
|
|
||||||
|
// NewRouterForTest builds the real route tree via SetupRoutes with
|
||||||
|
// the supplied middleware and handlers, bypassing the fx lifecycle
|
||||||
|
// and the HTTP listener. Tests use it so that route-group middleware
|
||||||
|
// registration order is exercised exactly as it ships, rather than
|
||||||
|
// against a hand-rebuilt chain that could drift from routes.go.
|
||||||
|
func NewRouterForTest(
|
||||||
|
log *slog.Logger,
|
||||||
|
cfg *config.Config,
|
||||||
|
mw *middleware.Middleware,
|
||||||
|
h *handlers.Handlers,
|
||||||
|
) http.Handler {
|
||||||
|
s := &Server{
|
||||||
|
log: log,
|
||||||
|
mw: mw,
|
||||||
|
h: h,
|
||||||
|
params: ServerParams{Config: cfg},
|
||||||
|
}
|
||||||
|
s.SetupRoutes()
|
||||||
|
|
||||||
|
return s.router
|
||||||
|
}
|
||||||
@@ -90,9 +90,11 @@ func (s *Server) setupRoutes() {
|
|||||||
|
|
||||||
func (s *Server) setupPageRoutes() {
|
func (s *Server) setupPageRoutes() {
|
||||||
s.router.Route("/pages", func(r chi.Router) {
|
s.router.Route("/pages", func(r chi.Router) {
|
||||||
|
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
||||||
|
// form, so the cap has to be installed before it runs.
|
||||||
|
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
|
||||||
|
|
||||||
r.Group(func(r chi.Router) {
|
r.Group(func(r chi.Router) {
|
||||||
r.Use(s.mw.LoginRateLimit())
|
r.Use(s.mw.LoginRateLimit())
|
||||||
@@ -106,6 +108,9 @@ func (s *Server) setupPageRoutes() {
|
|||||||
|
|
||||||
func (s *Server) setupUserRoutes() {
|
func (s *Server) setupUserRoutes() {
|
||||||
s.router.Route("/user/{username}", func(r chi.Router) {
|
s.router.Route("/user/{username}", func(r chi.Router) {
|
||||||
|
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
||||||
|
// form, so the cap has to be installed before it runs.
|
||||||
|
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
r.Use(s.mw.RequireAuth())
|
r.Use(s.mw.RequireAuth())
|
||||||
@@ -118,20 +123,24 @@ func (s *Server) setupUserRoutes() {
|
|||||||
|
|
||||||
func (s *Server) setupSourceRoutes() {
|
func (s *Server) setupSourceRoutes() {
|
||||||
s.router.Route("/sources", func(r chi.Router) {
|
s.router.Route("/sources", func(r chi.Router) {
|
||||||
|
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
||||||
|
// form, so the cap has to be installed before it runs.
|
||||||
|
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
r.Use(s.mw.RequireAuth())
|
r.Use(s.mw.RequireAuth())
|
||||||
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
|
||||||
r.Get("/", s.h.HandleSourceList())
|
r.Get("/", s.h.HandleSourceList())
|
||||||
r.Get("/new", s.h.HandleSourceCreate())
|
r.Get("/new", s.h.HandleSourceCreate())
|
||||||
r.Post("/new", s.h.HandleSourceCreateSubmit())
|
r.Post("/new", s.h.HandleSourceCreateSubmit())
|
||||||
})
|
})
|
||||||
|
|
||||||
s.router.Route("/source/{sourceID}", func(r chi.Router) {
|
s.router.Route("/source/{sourceID}", func(r chi.Router) {
|
||||||
|
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
||||||
|
// form, so the cap has to be installed before it runs.
|
||||||
|
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
r.Use(s.mw.RequireAuth())
|
r.Use(s.mw.RequireAuth())
|
||||||
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
|
||||||
r.Get("/", s.h.HandleSourceDetail())
|
r.Get("/", s.h.HandleSourceDetail())
|
||||||
r.Get("/edit", s.h.HandleSourceEdit())
|
r.Get("/edit", s.h.HandleSourceEdit())
|
||||||
r.Post("/edit", s.h.HandleSourceEditSubmit())
|
r.Post("/edit", s.h.HandleSourceEditSubmit())
|
||||||
|
|||||||
375
internal/server/routes_test.go
Normal file
375
internal/server/routes_test.go
Normal file
@@ -0,0 +1,375 @@
|
|||||||
|
package server_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"html"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"net/url"
|
||||||
|
"regexp"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/assert"
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
"go.uber.org/fx"
|
||||||
|
"go.uber.org/fx/fxtest"
|
||||||
|
"sneak.berlin/go/webhooker/internal/config"
|
||||||
|
"sneak.berlin/go/webhooker/internal/database"
|
||||||
|
"sneak.berlin/go/webhooker/internal/delivery"
|
||||||
|
"sneak.berlin/go/webhooker/internal/globals"
|
||||||
|
"sneak.berlin/go/webhooker/internal/handlers"
|
||||||
|
"sneak.berlin/go/webhooker/internal/healthcheck"
|
||||||
|
"sneak.berlin/go/webhooker/internal/logger"
|
||||||
|
"sneak.berlin/go/webhooker/internal/middleware"
|
||||||
|
"sneak.berlin/go/webhooker/internal/server"
|
||||||
|
"sneak.berlin/go/webhooker/internal/session"
|
||||||
|
)
|
||||||
|
|
||||||
|
// csrfCookieName is the cookie gorilla/csrf issues when it runs. Its
|
||||||
|
// presence or absence on a response is how these tests tell whether
|
||||||
|
// the CSRF middleware executed.
|
||||||
|
const csrfCookieName = "_gorilla_csrf"
|
||||||
|
|
||||||
|
type noopNotifier struct{}
|
||||||
|
|
||||||
|
func (n *noopNotifier) Notify([]delivery.Task) {}
|
||||||
|
|
||||||
|
// testEnv is the real router from routes.go plus the collaborators
|
||||||
|
// tests need to seed users and forge sessions.
|
||||||
|
type testEnv struct {
|
||||||
|
router http.Handler
|
||||||
|
sess *session.Session
|
||||||
|
db *database.Database
|
||||||
|
}
|
||||||
|
|
||||||
|
// newTestEnv wires the dependency graph with fx and builds the
|
||||||
|
// production route tree, so middleware registration order is
|
||||||
|
// exercised exactly as it ships.
|
||||||
|
func newTestEnv(t *testing.T) *testEnv {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
var (
|
||||||
|
log *logger.Logger
|
||||||
|
cfg *config.Config
|
||||||
|
mw *middleware.Middleware
|
||||||
|
hnd *handlers.Handlers
|
||||||
|
sess *session.Session
|
||||||
|
db *database.Database
|
||||||
|
)
|
||||||
|
|
||||||
|
app := fxtest.New(
|
||||||
|
t,
|
||||||
|
fx.Provide(
|
||||||
|
globals.New,
|
||||||
|
logger.New,
|
||||||
|
func() *config.Config {
|
||||||
|
return &config.Config{
|
||||||
|
DataDir: t.TempDir(),
|
||||||
|
Environment: config.EnvironmentDev,
|
||||||
|
}
|
||||||
|
},
|
||||||
|
database.New,
|
||||||
|
database.NewWebhookDBManager,
|
||||||
|
healthcheck.New,
|
||||||
|
session.New,
|
||||||
|
func() delivery.Notifier { return &noopNotifier{} },
|
||||||
|
middleware.New,
|
||||||
|
handlers.New,
|
||||||
|
),
|
||||||
|
fx.Populate(&log, &cfg, &mw, &hnd, &sess, &db),
|
||||||
|
)
|
||||||
|
app.RequireStart()
|
||||||
|
t.Cleanup(app.RequireStop)
|
||||||
|
|
||||||
|
return &testEnv{
|
||||||
|
router: server.NewRouterForTest(log.Get(), cfg, mw, hnd),
|
||||||
|
sess: sess,
|
||||||
|
db: db,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// oversizeValue returns a form value one byte past the route-group
|
||||||
|
// body cap, so an encoded form containing it is guaranteed oversize.
|
||||||
|
func oversizeValue() string {
|
||||||
|
return strings.Repeat("a", int(server.MaxFormBodySizeForTest)+1)
|
||||||
|
}
|
||||||
|
|
||||||
|
// csrfCookieSet reports whether the response issued a gorilla/csrf
|
||||||
|
// cookie, which only happens if the CSRF middleware ran.
|
||||||
|
func csrfCookieSet(w *httptest.ResponseRecorder) bool {
|
||||||
|
for _, c := range w.Result().Cookies() {
|
||||||
|
if c.Name == csrfCookieName {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// get issues a GET through the router with the supplied cookies.
|
||||||
|
func (e *testEnv) get(
|
||||||
|
path string,
|
||||||
|
cookies []*http.Cookie,
|
||||||
|
) *httptest.ResponseRecorder {
|
||||||
|
req := httptest.NewRequestWithContext(
|
||||||
|
context.Background(), http.MethodGet, path, nil,
|
||||||
|
)
|
||||||
|
|
||||||
|
for _, c := range cookies {
|
||||||
|
req.AddCookie(c)
|
||||||
|
}
|
||||||
|
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
e.router.ServeHTTP(w, req)
|
||||||
|
|
||||||
|
return w
|
||||||
|
}
|
||||||
|
|
||||||
|
// post issues a urlencoded form POST through the router. The body is
|
||||||
|
// a strings.Reader, so the request carries an accurate
|
||||||
|
// Content-Length — the signal MaxBodySize checks up front.
|
||||||
|
func (e *testEnv) post(
|
||||||
|
path string,
|
||||||
|
form url.Values,
|
||||||
|
cookies []*http.Cookie,
|
||||||
|
) *httptest.ResponseRecorder {
|
||||||
|
req := httptest.NewRequestWithContext(
|
||||||
|
context.Background(), http.MethodPost, path,
|
||||||
|
strings.NewReader(form.Encode()),
|
||||||
|
)
|
||||||
|
req.Header.Set(
|
||||||
|
"Content-Type", "application/x-www-form-urlencoded",
|
||||||
|
)
|
||||||
|
|
||||||
|
for _, c := range cookies {
|
||||||
|
req.AddCookie(c)
|
||||||
|
}
|
||||||
|
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
e.router.ServeHTTP(w, req)
|
||||||
|
|
||||||
|
return w
|
||||||
|
}
|
||||||
|
|
||||||
|
// csrfFrom renders the page at path and returns the CSRF token from
|
||||||
|
// its form together with every cookie needed for the follow-up POST.
|
||||||
|
func (e *testEnv) csrfFrom(
|
||||||
|
t *testing.T,
|
||||||
|
path string,
|
||||||
|
cookies []*http.Cookie,
|
||||||
|
) (string, []*http.Cookie) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
w := e.get(path, cookies)
|
||||||
|
require.Equal(t, http.StatusOK, w.Code)
|
||||||
|
|
||||||
|
pattern := regexp.MustCompile(
|
||||||
|
`name="csrf_token" value="([^"]+)"`,
|
||||||
|
)
|
||||||
|
|
||||||
|
match := pattern.FindStringSubmatch(w.Body.String())
|
||||||
|
require.Len(t, match, 2, "form must embed a CSRF token")
|
||||||
|
|
||||||
|
// html/template escapes "+" and "=" in attribute values, and
|
||||||
|
// gorilla/csrf tokens are standard base64, so the value read
|
||||||
|
// out of the markup has to be unescaped before it is submitted.
|
||||||
|
token := html.UnescapeString(match[1])
|
||||||
|
|
||||||
|
combined := make([]*http.Cookie, 0, len(cookies))
|
||||||
|
combined = append(combined, cookies...)
|
||||||
|
combined = append(combined, w.Result().Cookies()...)
|
||||||
|
|
||||||
|
return token, combined
|
||||||
|
}
|
||||||
|
|
||||||
|
// authCookies forges an authenticated session for the given user.
|
||||||
|
func (e *testEnv) authCookies(
|
||||||
|
t *testing.T,
|
||||||
|
userID, username string,
|
||||||
|
) []*http.Cookie {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
req := httptest.NewRequestWithContext(
|
||||||
|
context.Background(), http.MethodGet, "/setup", nil,
|
||||||
|
)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
|
||||||
|
s, err := e.sess.Get(req)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
e.sess.SetUser(s, userID, username)
|
||||||
|
require.NoError(t, e.sess.Save(req, w, s))
|
||||||
|
|
||||||
|
cookies := w.Result().Cookies()
|
||||||
|
require.NotEmpty(t, cookies, "session cookie should be set")
|
||||||
|
|
||||||
|
return cookies
|
||||||
|
}
|
||||||
|
|
||||||
|
// seedUser creates a user with the given password and returns the
|
||||||
|
// stored hash so tests can assert whether it later changed.
|
||||||
|
func (e *testEnv) seedUser(
|
||||||
|
t *testing.T,
|
||||||
|
username, password string,
|
||||||
|
) (string, string) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
hash, err := database.HashPassword(password)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
user := &database.User{Username: username, Password: hash}
|
||||||
|
require.NoError(t, e.db.DB().Create(user).Error)
|
||||||
|
|
||||||
|
return user.ID, hash
|
||||||
|
}
|
||||||
|
|
||||||
|
// storedHash reads the current password hash for a username.
|
||||||
|
func (e *testEnv) storedHash(t *testing.T, username string) string {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
var user database.User
|
||||||
|
|
||||||
|
require.NoError(t,
|
||||||
|
e.db.DB().Where("username = ?", username).
|
||||||
|
First(&user).Error,
|
||||||
|
)
|
||||||
|
|
||||||
|
return user.Password
|
||||||
|
}
|
||||||
|
|
||||||
|
// --- /pages group ---
|
||||||
|
|
||||||
|
// TestPagesLogin_OversizeBody_RejectedBeforeCSRF proves the cap runs
|
||||||
|
// ahead of gorilla/csrf: the response is a clean 413 and no CSRF
|
||||||
|
// cookie was issued, so neither the CSRF middleware nor the login
|
||||||
|
// handler ran.
|
||||||
|
func TestPagesLogin_OversizeBody_RejectedBeforeCSRF(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
env := newTestEnv(t)
|
||||||
|
|
||||||
|
form := url.Values{}
|
||||||
|
form.Set("username", oversizeValue())
|
||||||
|
form.Set("password", "irrelevant")
|
||||||
|
|
||||||
|
w := env.post("/pages/login", form, nil)
|
||||||
|
|
||||||
|
assert.Equal(
|
||||||
|
t, http.StatusRequestEntityTooLarge, w.Code,
|
||||||
|
)
|
||||||
|
assert.False(
|
||||||
|
t, csrfCookieSet(w),
|
||||||
|
"CSRF middleware must not run for an oversized body",
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPagesLogin_UnderLimit_NoToken_CSRFRejects is the control for
|
||||||
|
// the test above: an identically shaped but under-limit POST does
|
||||||
|
// reach gorilla/csrf, which rejects it and issues its cookie. Without
|
||||||
|
// this, the missing-cookie assertion above would prove nothing.
|
||||||
|
func TestPagesLogin_UnderLimit_NoToken_CSRFRejects(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
env := newTestEnv(t)
|
||||||
|
|
||||||
|
form := url.Values{}
|
||||||
|
form.Set("username", "someone")
|
||||||
|
form.Set("password", "irrelevant")
|
||||||
|
|
||||||
|
w := env.post("/pages/login", form, nil)
|
||||||
|
|
||||||
|
assert.Equal(t, http.StatusForbidden, w.Code)
|
||||||
|
assert.True(
|
||||||
|
t, csrfCookieSet(w),
|
||||||
|
"CSRF middleware should run for an under-limit body",
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPagesLogin_UnderLimit_ValidToken_ReachesHandler proves the
|
||||||
|
// reorder did not break CSRF token handling: a token harvested from
|
||||||
|
// the rendered login form is still accepted and the request lands in
|
||||||
|
// the handler.
|
||||||
|
func TestPagesLogin_UnderLimit_ValidToken_ReachesHandler(
|
||||||
|
t *testing.T,
|
||||||
|
) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
env := newTestEnv(t)
|
||||||
|
|
||||||
|
token, cookies := env.csrfFrom(t, "/pages/login", nil)
|
||||||
|
|
||||||
|
form := url.Values{}
|
||||||
|
form.Set("csrf_token", token)
|
||||||
|
form.Set("username", "nosuchuser")
|
||||||
|
form.Set("password", "wrongpassword")
|
||||||
|
|
||||||
|
w := env.post("/pages/login", form, cookies)
|
||||||
|
|
||||||
|
assert.Equal(t, http.StatusUnauthorized, w.Code)
|
||||||
|
assert.Contains(
|
||||||
|
t, w.Body.String(), "Invalid username or password",
|
||||||
|
"request should reach the login handler",
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
// --- /user/{username} group ---
|
||||||
|
|
||||||
|
// TestPasswordChange_OversizeBody_RejectedAndPasswordUnchanged
|
||||||
|
// covers the route that previously had no middleware body cap at
|
||||||
|
// all. The request carries a valid session and a valid CSRF token,
|
||||||
|
// so the only thing that can stop it is the size cap; the unchanged
|
||||||
|
// password hash is the observable proof the handler never ran.
|
||||||
|
func TestPasswordChange_OversizeBody_RejectedAndPasswordUnchanged(
|
||||||
|
t *testing.T,
|
||||||
|
) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
env := newTestEnv(t)
|
||||||
|
|
||||||
|
userID, originalHash := env.seedUser(t, "pwuser", "oldpassword")
|
||||||
|
cookies := env.authCookies(t, userID, "pwuser")
|
||||||
|
token, cookies := env.csrfFrom(t, "/user/pwuser/", cookies)
|
||||||
|
|
||||||
|
form := url.Values{}
|
||||||
|
form.Set("csrf_token", token)
|
||||||
|
form.Set("current_password", "oldpassword")
|
||||||
|
form.Set("new_password", oversizeValue())
|
||||||
|
form.Set("confirm_password", oversizeValue())
|
||||||
|
|
||||||
|
w := env.post("/user/pwuser/password", form, cookies)
|
||||||
|
|
||||||
|
assert.Equal(
|
||||||
|
t, http.StatusRequestEntityTooLarge, w.Code,
|
||||||
|
)
|
||||||
|
assert.Equal(
|
||||||
|
t, originalHash, env.storedHash(t, "pwuser"),
|
||||||
|
"handler must not run, so the password must be unchanged",
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPasswordChange_UnderLimit_Succeeds proves that adding the cap
|
||||||
|
// to the /user/{username} group did not break the route it guards.
|
||||||
|
func TestPasswordChange_UnderLimit_Succeeds(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
env := newTestEnv(t)
|
||||||
|
|
||||||
|
userID, originalHash := env.seedUser(t, "okuser", "oldpassword")
|
||||||
|
cookies := env.authCookies(t, userID, "okuser")
|
||||||
|
token, cookies := env.csrfFrom(t, "/user/okuser/", cookies)
|
||||||
|
|
||||||
|
form := url.Values{}
|
||||||
|
form.Set("csrf_token", token)
|
||||||
|
form.Set("current_password", "oldpassword")
|
||||||
|
form.Set("new_password", "brandnewpassword")
|
||||||
|
form.Set("confirm_password", "brandnewpassword")
|
||||||
|
|
||||||
|
w := env.post("/user/okuser/password", form, cookies)
|
||||||
|
|
||||||
|
assert.Equal(t, http.StatusOK, w.Code)
|
||||||
|
assert.NotEqual(
|
||||||
|
t, originalHash, env.storedHash(t, "okuser"),
|
||||||
|
"an under-limit password change should still apply",
|
||||||
|
)
|
||||||
|
}
|
||||||
@@ -10,7 +10,6 @@ import (
|
|||||||
"log/slog"
|
"log/slog"
|
||||||
"maps"
|
"maps"
|
||||||
"net/http"
|
"net/http"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/gorilla/sessions"
|
"github.com/gorilla/sessions"
|
||||||
"go.uber.org/fx"
|
"go.uber.org/fx"
|
||||||
@@ -33,18 +32,6 @@ const (
|
|||||||
// status.
|
// status.
|
||||||
AuthenticatedKey = "authenticated"
|
AuthenticatedKey = "authenticated"
|
||||||
|
|
||||||
// CreatedAtKey is the session key holding the Unix timestamp at
|
|
||||||
// which the session was authenticated. It anchors the ABSOLUTE
|
|
||||||
// expiry clock and is written exactly once, by SetUser. Nothing
|
|
||||||
// refreshes it: an absolute deadline that moved with activity
|
|
||||||
// would not be a cap at all.
|
|
||||||
CreatedAtKey = "created_at"
|
|
||||||
|
|
||||||
// LastSeenKey is the session key holding the Unix timestamp of
|
|
||||||
// the most recent authenticated request. It anchors the IDLE
|
|
||||||
// expiry clock and is pushed forward by Touch.
|
|
||||||
LastSeenKey = "last_seen"
|
|
||||||
|
|
||||||
// sessionKeyLength is the required length in bytes for the
|
// sessionKeyLength is the required length in bytes for the
|
||||||
// session authentication key.
|
// session authentication key.
|
||||||
sessionKeyLength = 32
|
sessionKeyLength = 32
|
||||||
@@ -54,19 +41,6 @@ const (
|
|||||||
|
|
||||||
// secondsPerDay is the number of seconds in a day.
|
// secondsPerDay is the number of seconds in a day.
|
||||||
secondsPerDay = 86400
|
secondsPerDay = 86400
|
||||||
|
|
||||||
// sessionAbsoluteMaxAge is the hard upper bound on how long a
|
|
||||||
// session may live, measured from CreatedAtKey. Activity never
|
|
||||||
// extends it, so even a continuously used session ends here and
|
|
||||||
// the user has to authenticate again.
|
|
||||||
sessionAbsoluteMaxAge = sessionMaxAgeDays * secondsPerDay * time.Second
|
|
||||||
|
|
||||||
// idleRefreshDivisor rate-limits idle-deadline refreshes. Touch
|
|
||||||
// only rewrites LastSeenKey once the stored value is older than
|
|
||||||
// idleTimeout/idleRefreshDivisor, so an active session is
|
|
||||||
// re-saved at most this many times per idle window instead of
|
|
||||||
// once per request. See Touch for the tradeoff this buys.
|
|
||||||
idleRefreshDivisor = 10
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// ErrSessionKeyLength is returned when the decoded session key
|
// ErrSessionKeyLength is returned when the decoded session key
|
||||||
@@ -88,16 +62,6 @@ type Session struct {
|
|||||||
key []byte // raw 32-byte auth key, also used for CSRF cookie signing
|
key []byte // raw 32-byte auth key, also used for CSRF cookie signing
|
||||||
log *slog.Logger
|
log *slog.Logger
|
||||||
config *config.Config
|
config *config.Config
|
||||||
|
|
||||||
// idleTimeout is the sliding inactivity window. A session that
|
|
||||||
// sees no authenticated request within this window expires,
|
|
||||||
// independently of the absolute cap. Non-positive disables idle
|
|
||||||
// expiry and leaves sessionAbsoluteMaxAge as the only bound.
|
|
||||||
idleTimeout time.Duration
|
|
||||||
|
|
||||||
// now reads the current time. Injected so expiry can be tested
|
|
||||||
// without sleeping.
|
|
||||||
now func() time.Time
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// New creates a new session manager. The cookie store is
|
// New creates a new session manager. The cookie store is
|
||||||
@@ -111,8 +75,6 @@ func New(
|
|||||||
s := &Session{
|
s := &Session{
|
||||||
log: params.Logger.Get(),
|
log: params.Logger.Get(),
|
||||||
config: params.Config,
|
config: params.Config,
|
||||||
idleTimeout: params.Config.SessionIdleTimeout,
|
|
||||||
now: time.Now,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
lc.Append(fx.Hook{
|
lc.Append(fx.Hook{
|
||||||
@@ -187,98 +149,29 @@ func (s *Session) Save(
|
|||||||
return sess.Save(r, w)
|
return sess.Save(r, w)
|
||||||
}
|
}
|
||||||
|
|
||||||
// SetUser sets the user information in the session. It starts both
|
// SetUser sets the user information in the session.
|
||||||
// expiry clocks: CreatedAtKey (absolute, never refreshed again) and
|
|
||||||
// LastSeenKey (idle, refreshed by Touch).
|
|
||||||
func (s *Session) SetUser(
|
func (s *Session) SetUser(
|
||||||
sess *sessions.Session,
|
sess *sessions.Session,
|
||||||
userID, username string,
|
userID, username string,
|
||||||
) {
|
) {
|
||||||
now := s.now().Unix()
|
|
||||||
|
|
||||||
sess.Values[UserIDKey] = userID
|
sess.Values[UserIDKey] = userID
|
||||||
sess.Values[UsernameKey] = username
|
sess.Values[UsernameKey] = username
|
||||||
sess.Values[AuthenticatedKey] = true
|
sess.Values[AuthenticatedKey] = true
|
||||||
sess.Values[CreatedAtKey] = now
|
|
||||||
sess.Values[LastSeenKey] = now
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// ClearUser removes user information from the session, including
|
// ClearUser removes user information from the session.
|
||||||
// both expiry timestamps.
|
|
||||||
func (s *Session) ClearUser(sess *sessions.Session) {
|
func (s *Session) ClearUser(sess *sessions.Session) {
|
||||||
delete(sess.Values, UserIDKey)
|
delete(sess.Values, UserIDKey)
|
||||||
delete(sess.Values, UsernameKey)
|
delete(sess.Values, UsernameKey)
|
||||||
delete(sess.Values, AuthenticatedKey)
|
delete(sess.Values, AuthenticatedKey)
|
||||||
delete(sess.Values, CreatedAtKey)
|
|
||||||
delete(sess.Values, LastSeenKey)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// sessionTime reads a Unix-second timestamp stored under key.
|
// IsAuthenticated checks if the session has an authenticated
|
||||||
func sessionTime(
|
// user.
|
||||||
sess *sessions.Session,
|
|
||||||
key string,
|
|
||||||
) (time.Time, bool) {
|
|
||||||
secs, ok := sess.Values[key].(int64)
|
|
||||||
if !ok {
|
|
||||||
return time.Time{}, false
|
|
||||||
}
|
|
||||||
|
|
||||||
return time.Unix(secs, 0), true
|
|
||||||
}
|
|
||||||
|
|
||||||
// IsAuthenticated checks if the session has an authenticated user
|
|
||||||
// whose session has not passed either expiry deadline. Every
|
|
||||||
// authentication decision goes through here, so neither clock can
|
|
||||||
// be bypassed by a caller that forgets to check it.
|
|
||||||
func (s *Session) IsAuthenticated(sess *sessions.Session) bool {
|
func (s *Session) IsAuthenticated(sess *sessions.Session) bool {
|
||||||
auth, ok := sess.Values[AuthenticatedKey].(bool)
|
auth, ok := sess.Values[AuthenticatedKey].(bool)
|
||||||
if !ok || !auth {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
return !s.expired(sess)
|
return ok && auth
|
||||||
}
|
|
||||||
|
|
||||||
// Touch records authenticated activity by pushing the IDLE deadline
|
|
||||||
// forward. It writes LastSeenKey only; CreatedAtKey is left alone so
|
|
||||||
// the absolute cap keeps counting down even for a user who never
|
|
||||||
// stops clicking.
|
|
||||||
//
|
|
||||||
// Callers must only invoke Touch for a request that authenticated
|
|
||||||
// with this session. Refreshing on an unauthenticated request would
|
|
||||||
// let anyone holding a stolen or abandoned cookie keep the session
|
|
||||||
// alive by polling a public endpoint. Touch enforces that itself by
|
|
||||||
// returning false for any session that is not currently
|
|
||||||
// authenticated and unexpired.
|
|
||||||
//
|
|
||||||
// To avoid re-encrypting and re-emitting the session cookie on every
|
|
||||||
// single request, the timestamp is advanced only once it is older
|
|
||||||
// than idleTimeout/idleRefreshDivisor. The tradeoff is that
|
|
||||||
// LastSeenKey lags real activity by up to that much, so a session
|
|
||||||
// can expire slightly early relative to the user's true last
|
|
||||||
// request -- never late.
|
|
||||||
//
|
|
||||||
// Touch reports whether it changed the session; only then does the
|
|
||||||
// caller need to save it.
|
|
||||||
func (s *Session) Touch(sess *sessions.Session) bool {
|
|
||||||
if s.idleTimeout <= 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
if !s.IsAuthenticated(sess) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
now := s.now()
|
|
||||||
|
|
||||||
lastSeen, ok := sessionTime(sess, LastSeenKey)
|
|
||||||
if ok && now.Sub(lastSeen) < s.idleTimeout/idleRefreshDivisor {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
sess.Values[LastSeenKey] = now.Unix()
|
|
||||||
|
|
||||||
return true
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// GetUserID retrieves the user ID from the session.
|
// GetUserID retrieves the user ID from the session.
|
||||||
@@ -360,41 +253,3 @@ func (s *Session) Regenerate(
|
|||||||
|
|
||||||
return newSess, nil
|
return newSess, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// expired reports whether the session has passed either of its two
|
|
||||||
// independent deadlines. They are deliberately kept apart:
|
|
||||||
//
|
|
||||||
// - the ABSOLUTE deadline is CreatedAtKey + sessionAbsoluteMaxAge.
|
|
||||||
// It is fixed at login and no amount of activity moves it.
|
|
||||||
// - the IDLE deadline is LastSeenKey + idleTimeout. Activity moves
|
|
||||||
// it forward via Touch.
|
|
||||||
//
|
|
||||||
// Whichever comes first ends the session.
|
|
||||||
//
|
|
||||||
// A session that claims to be authenticated but carries no
|
|
||||||
// timestamps predates this check; it is treated as expired so the
|
|
||||||
// user re-authenticates rather than being granted an unbounded
|
|
||||||
// session.
|
|
||||||
func (s *Session) expired(sess *sessions.Session) bool {
|
|
||||||
now := s.now()
|
|
||||||
|
|
||||||
createdAt, ok := sessionTime(sess, CreatedAtKey)
|
|
||||||
if !ok {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
if !now.Before(createdAt.Add(sessionAbsoluteMaxAge)) {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
if s.idleTimeout <= 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
lastSeen, ok := sessionTime(sess, LastSeenKey)
|
|
||||||
if !ok {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
return !now.Before(lastSeen.Add(s.idleTimeout))
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import (
|
|||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"os"
|
"os"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/gorilla/sessions"
|
"github.com/gorilla/sessions"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
@@ -18,47 +17,11 @@ import (
|
|||||||
|
|
||||||
const testKeySize = 32
|
const testKeySize = 32
|
||||||
|
|
||||||
// testIdleTimeout is the idle window used by the expiry tests.
|
// testSession creates a Session with a real cookie store for
|
||||||
const testIdleTimeout = time.Hour
|
// testing.
|
||||||
|
|
||||||
// testAbsoluteMaxAge restates the documented absolute session cap
|
|
||||||
// independently of the implementation constant.
|
|
||||||
const testAbsoluteMaxAge = 7 * 24 * time.Hour
|
|
||||||
|
|
||||||
// fakeClock is a manually advanced clock, so expiry can be tested
|
|
||||||
// without sleeping.
|
|
||||||
type fakeClock struct {
|
|
||||||
t time.Time
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *fakeClock) Now() time.Time {
|
|
||||||
return c.t
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *fakeClock) Advance(d time.Duration) {
|
|
||||||
c.t = c.t.Add(d)
|
|
||||||
}
|
|
||||||
|
|
||||||
// testSession creates a Session with a real cookie store and the
|
|
||||||
// real clock.
|
|
||||||
func testSession(t *testing.T) *session.Session {
|
func testSession(t *testing.T) *session.Session {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
s, _ := testSessionWithClock(t, testIdleTimeout, nil)
|
|
||||||
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
|
|
||||||
// testSessionWithClock creates a Session with a real cookie store,
|
|
||||||
// the given idle timeout, and a manually advanced clock. Passing a
|
|
||||||
// nil clock uses the real one.
|
|
||||||
func testSessionWithClock(
|
|
||||||
t *testing.T,
|
|
||||||
idleTimeout time.Duration,
|
|
||||||
clock *fakeClock,
|
|
||||||
) (*session.Session, *fakeClock) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
key := make([]byte, testKeySize)
|
key := make([]byte, testKeySize)
|
||||||
|
|
||||||
for i := range key {
|
for i := range key {
|
||||||
@@ -76,7 +39,6 @@ func testSessionWithClock(
|
|||||||
|
|
||||||
cfg := &config.Config{
|
cfg := &config.Config{
|
||||||
Environment: config.EnvironmentDev,
|
Environment: config.EnvironmentDev,
|
||||||
SessionIdleTimeout: idleTimeout,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
log := slog.New(slog.NewTextHandler(
|
log := slog.New(slog.NewTextHandler(
|
||||||
@@ -84,46 +46,7 @@ func testSessionWithClock(
|
|||||||
&slog.HandlerOptions{Level: slog.LevelDebug},
|
&slog.HandlerOptions{Level: slog.LevelDebug},
|
||||||
))
|
))
|
||||||
|
|
||||||
var now func() time.Time
|
return session.NewForTest(store, cfg, log, key)
|
||||||
|
|
||||||
if clock != nil {
|
|
||||||
now = clock.Now
|
|
||||||
}
|
|
||||||
|
|
||||||
return session.NewForTest(store, cfg, log, key, now), clock
|
|
||||||
}
|
|
||||||
|
|
||||||
// newFakeClock returns a clock started at a fixed instant.
|
|
||||||
func newFakeClock() *fakeClock {
|
|
||||||
return &fakeClock{
|
|
||||||
t: time.Date(
|
|
||||||
2026, time.January, 2, 3, 4, 5, 0, time.UTC,
|
|
||||||
),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// authenticatedSession returns a fresh session that has just been
|
|
||||||
// logged in, along with its manager and clock.
|
|
||||||
func authenticatedSession(
|
|
||||||
t *testing.T,
|
|
||||||
idleTimeout time.Duration,
|
|
||||||
) (*session.Session, *sessions.Session, *fakeClock) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
s, clock := testSessionWithClock(
|
|
||||||
t, idleTimeout, newFakeClock(),
|
|
||||||
)
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, "/", nil)
|
|
||||||
|
|
||||||
sess, err := s.Get(req)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
s.SetUser(sess, "user-123", "alice")
|
|
||||||
require.True(t, s.IsAuthenticated(sess))
|
|
||||||
|
|
||||||
return s, sess, clock
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- Get and Save Tests ---
|
// --- Get and Save Tests ---
|
||||||
@@ -507,263 +430,6 @@ func TestSessionConstants(t *testing.T) {
|
|||||||
assert.Equal(t, "user_id", session.UserIDKey)
|
assert.Equal(t, "user_id", session.UserIDKey)
|
||||||
assert.Equal(t, "username", session.UsernameKey)
|
assert.Equal(t, "username", session.UsernameKey)
|
||||||
assert.Equal(t, "authenticated", session.AuthenticatedKey)
|
assert.Equal(t, "authenticated", session.AuthenticatedKey)
|
||||||
assert.Equal(t, "created_at", session.CreatedAtKey)
|
|
||||||
assert.Equal(t, "last_seen", session.LastSeenKey)
|
|
||||||
}
|
|
||||||
|
|
||||||
// --- Expiry Tests ---
|
|
||||||
|
|
||||||
func TestSetUser_StartsBothClocks(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
_, sess, clock := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t, clock.Now().Unix(), sess.Values[session.CreatedAtKey],
|
|
||||||
"SetUser should anchor the absolute clock",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, clock.Now().Unix(), sess.Values[session.LastSeenKey],
|
|
||||||
"SetUser should anchor the idle clock",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIsAuthenticated_WithinIdleWindow(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
clock.Advance(testIdleTimeout - time.Second)
|
|
||||||
|
|
||||||
assert.True(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"session should still be valid just inside the idle window",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIsAuthenticated_IdleExpired(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
clock.Advance(testIdleTimeout)
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"session should expire once the idle window lapses",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestTouch_DoesNotExtendAbsoluteCap is the regression test for the
|
|
||||||
// refresh-the-wrong-clock bug: a session that is used continuously
|
|
||||||
// must survive well past the idle window and still die at the
|
|
||||||
// absolute cap.
|
|
||||||
func TestTouch_DoesNotExtendAbsoluteCap(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
createdAt := sess.Values[session.CreatedAtKey]
|
|
||||||
|
|
||||||
// Stay active: a request every half idle window, right up to
|
|
||||||
// the absolute cap.
|
|
||||||
step := testIdleTimeout / 2
|
|
||||||
steps := int(testAbsoluteMaxAge/step) - 1
|
|
||||||
|
|
||||||
for i := range steps {
|
|
||||||
clock.Advance(step)
|
|
||||||
s.Touch(sess)
|
|
||||||
|
|
||||||
require.True(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"active session should survive the idle window "+
|
|
||||||
"(step %d of %d)", i+1, steps,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// One more step of activity takes the session to exactly the
|
|
||||||
// absolute cap, measured from login. Nothing that happened in
|
|
||||||
// the loop may have moved that deadline.
|
|
||||||
clock.Advance(step)
|
|
||||||
s.Touch(sess)
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"activity must not extend the absolute cap",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, createdAt, sess.Values[session.CreatedAtKey],
|
|
||||||
"Touch must never rewrite the absolute-clock anchor",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestTouch_RefreshesIdleDeadline(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
// Halfway through the window, activity happens.
|
|
||||||
clock.Advance(testIdleTimeout / 2)
|
|
||||||
assert.True(
|
|
||||||
t, s.Touch(sess),
|
|
||||||
"Touch should refresh once past the lazy-refresh threshold",
|
|
||||||
)
|
|
||||||
|
|
||||||
// Past the original deadline, but inside the refreshed one.
|
|
||||||
clock.Advance(testIdleTimeout - time.Second)
|
|
||||||
assert.True(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"refreshed session should outlive the original deadline",
|
|
||||||
)
|
|
||||||
|
|
||||||
// And it still expires an idle window after that activity.
|
|
||||||
clock.Advance(time.Second)
|
|
||||||
assert.False(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"refreshed session should expire one window after activity",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestTouch_LazyBelowRefreshThreshold(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
before := sess.Values[session.LastSeenKey]
|
|
||||||
|
|
||||||
// A request arriving almost immediately is not worth a cookie
|
|
||||||
// rewrite.
|
|
||||||
clock.Advance(time.Second)
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.Touch(sess),
|
|
||||||
"Touch should not rewrite the session below the threshold",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, before, sess.Values[session.LastSeenKey],
|
|
||||||
"last-seen should be unchanged below the threshold",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestTouch_UnauthenticatedSessionIsNotRefreshed(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, clock := testSessionWithClock(
|
|
||||||
t, testIdleTimeout, newFakeClock(),
|
|
||||||
)
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, "/", nil)
|
|
||||||
|
|
||||||
sess, err := s.Get(req)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
clock.Advance(testIdleTimeout / 2)
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.Touch(sess),
|
|
||||||
"an unauthenticated session must not be refreshed",
|
|
||||||
)
|
|
||||||
|
|
||||||
_, hasLastSeen := sess.Values[session.LastSeenKey]
|
|
||||||
assert.False(
|
|
||||||
t, hasLastSeen,
|
|
||||||
"Touch must not stamp an unauthenticated session",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestTouch_IdleExpiredSessionIsNotRevived(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
clock.Advance(testIdleTimeout)
|
|
||||||
require.False(t, s.IsAuthenticated(sess))
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.Touch(sess),
|
|
||||||
"an already expired session must not be refreshed",
|
|
||||||
)
|
|
||||||
assert.False(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"Touch must not revive an expired session",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIsAuthenticated_MissingTimestamps(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, _ := testSessionWithClock(
|
|
||||||
t, testIdleTimeout, newFakeClock(),
|
|
||||||
)
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, "/", nil)
|
|
||||||
|
|
||||||
sess, err := s.Get(req)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
// A session from before idle expiry existed: authenticated,
|
|
||||||
// but with no timestamps. Fail closed.
|
|
||||||
sess.Values[session.AuthenticatedKey] = true
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"a session with no timestamps should be rejected",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIsAuthenticated_MissingLastSeen(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, _ := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
delete(sess.Values, session.LastSeenKey)
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"a session with no idle anchor should be rejected",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIdleTimeoutDisabled_AbsoluteCapStillApplies(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, clock := authenticatedSession(t, 0)
|
|
||||||
|
|
||||||
// Idle expiry is off, so an untouched session survives an
|
|
||||||
// arbitrary idle stretch.
|
|
||||||
clock.Advance(testAbsoluteMaxAge - time.Second)
|
|
||||||
assert.True(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"idle expiry should be disabled by a non-positive timeout",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, s.Touch(sess),
|
|
||||||
"Touch should be a no-op when idle expiry is disabled",
|
|
||||||
)
|
|
||||||
|
|
||||||
// The absolute cap still ends it.
|
|
||||||
clock.Advance(time.Second)
|
|
||||||
assert.False(
|
|
||||||
t, s.IsAuthenticated(sess),
|
|
||||||
"the absolute cap must still apply with idle expiry off",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestClearUser_RemovesTimestamps(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
s, sess, _ := authenticatedSession(t, testIdleTimeout)
|
|
||||||
|
|
||||||
s.ClearUser(sess)
|
|
||||||
|
|
||||||
_, hasCreatedAt := sess.Values[session.CreatedAtKey]
|
|
||||||
assert.False(t, hasCreatedAt, "CreatedAtKey should be removed")
|
|
||||||
|
|
||||||
_, hasLastSeen := sess.Values[session.LastSeenKey]
|
|
||||||
assert.False(t, hasLastSeen, "LastSeenKey should be removed")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- Edge Cases ---
|
// --- Edge Cases ---
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ package session
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/gorilla/sessions"
|
"github.com/gorilla/sessions"
|
||||||
"sneak.berlin/go/webhooker/internal/config"
|
"sneak.berlin/go/webhooker/internal/config"
|
||||||
@@ -13,28 +12,16 @@ import (
|
|||||||
// middleware and handler tests to use real session functionality. The key
|
// middleware and handler tests to use real session functionality. The key
|
||||||
// parameter is the raw 32-byte authentication key used for session encryption
|
// parameter is the raw 32-byte authentication key used for session encryption
|
||||||
// and CSRF cookie signing.
|
// and CSRF cookie signing.
|
||||||
//
|
|
||||||
// The idle timeout is taken from cfg.SessionIdleTimeout, exactly as in
|
|
||||||
// production. The now parameter supplies the clock used for expiry
|
|
||||||
// checks so tests can advance time without sleeping; pass nil for the
|
|
||||||
// real clock.
|
|
||||||
func NewForTest(
|
func NewForTest(
|
||||||
store *sessions.CookieStore,
|
store *sessions.CookieStore,
|
||||||
cfg *config.Config,
|
cfg *config.Config,
|
||||||
log *slog.Logger,
|
log *slog.Logger,
|
||||||
key []byte,
|
key []byte,
|
||||||
now func() time.Time,
|
|
||||||
) *Session {
|
) *Session {
|
||||||
if now == nil {
|
|
||||||
now = time.Now
|
|
||||||
}
|
|
||||||
|
|
||||||
return &Session{
|
return &Session{
|
||||||
store: store,
|
store: store,
|
||||||
key: key,
|
key: key,
|
||||||
config: cfg,
|
config: cfg,
|
||||||
log: log,
|
log: log,
|
||||||
idleTimeout: cfg.SessionIdleTimeout,
|
|
||||||
now: now,
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user