Build the middleware test cookie stores with the production constructor (closes #154) #434

Merged
clawbot merged 1 commits from issue-154-session-test-store into next 2026-10-02 14:30:52 +02:00
Collaborator

The middleware tests built their session cookie stores by hand, setting store.Options directly. That leaves the store's cookie codecs at the library's 30-day default instead of the 7-day cap production applies through store.MaxAge, so the tests ran against a store the application never uses.

session.NewStore now lives in internal/session/testing.go rather than internal/session/export_test.go, which only the session package's own tests could see. Both middleware test helpers build their store through it, and the now-empty export_test.go is deleted.

Things the diff does not show:

  • The production store's Secure attribute is a template set to true, where the old test store set it to false. Every write path overwrites it from the request's transport, so the middleware tests over plain HTTP still get non-Secure cookies; none of their assertions changed.
  • The metrics authentication helper's store previously used a 1-day cookie lifetime; it now uses the production 7-day one. Nothing in those tests depends on it.

Fixes #154

Model: opus-5-5

The middleware tests built their session cookie stores by hand, setting `store.Options` directly. That leaves the store's cookie codecs at the library's 30-day default instead of the 7-day cap production applies through `store.MaxAge`, so the tests ran against a store the application never uses. `session.NewStore` now lives in `internal/session/testing.go` rather than `internal/session/export_test.go`, which only the session package's own tests could see. Both middleware test helpers build their store through it, and the now-empty `export_test.go` is deleted. Things the diff does not show: - The production store's Secure attribute is a template set to true, where the old test store set it to false. Every write path overwrites it from the request's transport, so the middleware tests over plain HTTP still get non-Secure cookies; none of their assertions changed. - The metrics authentication helper's store previously used a 1-day cookie lifetime; it now uses the production 7-day one. Nothing in those tests depends on it. Fixes https://git.eeqj.de/sneak/webhooker/issues/154 Model: opus-5-5
clawbot added the needs-review label 2026-10-02 13:23:45 +02:00
clawbot self-assigned this 2026-10-02 13:23:46 +02:00
clawbot added 1 commit 2026-10-02 13:23:46 +02:00
session.NewStore moves from internal/session/export_test.go into
internal/session/testing.go, so packages outside session can build the
store the application runs with. The two middleware test helpers that
assembled their own store by assigning store.Options now call it, which
puts their securecookie codecs on the same 7-day cap as production
instead of the library's 30-day default.

Model: opus-5-5
Author
Collaborator

Review passed: the middleware tests now build their cookie stores with the production constructor, and nothing else changes.

Model: opus-5-5

Review passed: the middleware tests now build their cookie stores with the production constructor, and nothing else changes. Model: opus-5-5
clawbot merged commit 0f9b68a0e8 into next 2026-10-02 14:30:52 +02:00
clawbot deleted branch issue-154-session-test-store 2026-10-02 14:30:52 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#434