A new database brings a new session key, but the browser keeps its session and CSRF cookies signed with the old one. gorilla/csrf already replaced the CSRF cookie; Session.Get returned the session cookie's decode error, which the login handler answered with a 500. Get now treats a cookie that does not decode as absent: every caller gets a new, empty session, and logging in replaces the cookie.
A start that creates webhooker.db now logs created a new, empty database at WARN with its path, two lines above the first-boot banner; a start on an existing database logs connected to database as before. The README says what the line means.
Tests: a routed login carrying both stale cookies, and the new-database line.
Not visible in the diff:
The routes tests' csrfFrom now lets a cookie the page sets replace a held one of the same name, as a browser does. Before, both were sent and the server read the stale one.
The codec tests decode through the store, because Get no longer passes on the codec's reason.
The err branches after Get in its callers are unchanged; a bad cookie no longer reaches them, so logout now replaces a stale cookie instead of leaving it.
Why the database was new is on the issue: by elimination, the upaas app has no volume at /var/lib/webhooker; its settings were not seen.
Judgement call: WARN rather than INFO, since the process cannot tell a first start from a lost data directory.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/webhooker/issues/359.
A new database brings a new session key, but the browser keeps its session and CSRF cookies signed with the old one. gorilla/csrf already replaced the CSRF cookie; `Session.Get` returned the session cookie's decode error, which the login handler answered with a 500. `Get` now treats a cookie that does not decode as absent: every caller gets a new, empty session, and logging in replaces the cookie.
A start that creates `webhooker.db` now logs `created a new, empty database` at `WARN` with its path, two lines above the first-boot banner; a start on an existing database logs `connected to database` as before. The README says what the line means.
Tests: a routed login carrying both stale cookies, and the new-database line.
Not visible in the diff:
- The routes tests' `csrfFrom` now lets a cookie the page sets replace a held one of the same name, as a browser does. Before, both were sent and the server read the stale one.
- The codec tests decode through the store, because `Get` no longer passes on the codec's reason.
- The `err` branches after `Get` in its callers are unchanged; a bad cookie no longer reaches them, so logout now replaces a stale cookie instead of leaving it.
- Why the database was new is on the issue: by elimination, the upaas app has no volume at `/var/lib/webhooker`; its settings were not seen.
Judgement call: `WARN` rather than `INFO`, since the process cannot tell a first start from a lost data directory.
Model: opus-5-5
A new database brings a new session key. A browser still holding the
old session cookie got a 500 on a correct login: Session.Get returned
the cookie's decode error and the login handler answered it with a
500. Get now treats a cookie that does not decode as absent, and
logging in replaces it. gorilla/csrf already did the same for the
CSRF cookie.
A start that creates webhooker.db now logs "created a new, empty
database" at WARN with its path, shortly before the first-boot banner,
so an unexpectedly empty DATA_DIR is noticed.
The codec tests now decode through the store, since Get no longer
reports the codec's reason.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #359.
A new database brings a new session key, but the browser keeps its session and CSRF cookies signed with the old one. gorilla/csrf already replaced the CSRF cookie;
Session.Getreturned the session cookie's decode error, which the login handler answered with a 500.Getnow treats a cookie that does not decode as absent: every caller gets a new, empty session, and logging in replaces the cookie.A start that creates
webhooker.dbnow logscreated a new, empty databaseatWARNwith its path, two lines above the first-boot banner; a start on an existing database logsconnected to databaseas before. The README says what the line means.Tests: a routed login carrying both stale cookies, and the new-database line.
Not visible in the diff:
csrfFromnow lets a cookie the page sets replace a held one of the same name, as a browser does. Before, both were sent and the server read the stale one.Getno longer passes on the codec's reason.errbranches afterGetin its callers are unchanged; a bad cookie no longer reaches them, so logout now replaces a stale cookie instead of leaving it./var/lib/webhooker; its settings were not seen.Judgement call:
WARNrather thanINFO, since the process cannot tell a first start from a lost data directory.Model: opus-5-5
Review passed.
Model: opus-5-5