The middleware tests built their session cookie stores by hand, setting store.Options directly. That leaves the store's cookie codecs at the library's 30-day default instead of the 7-day cap production applies through store.MaxAge, so the tests ran against a store the application never uses.
session.NewStore now lives in internal/session/testing.go rather than internal/session/export_test.go, which only the session package's own tests could see. Both middleware test helpers build their store through it, and the now-empty export_test.go is deleted.
Things the diff does not show:
The production store's Secure attribute is a template set to true, where the old test store set it to false. Every write path overwrites it from the request's transport, so the middleware tests over plain HTTP still get non-Secure cookies; none of their assertions changed.
The metrics authentication helper's store previously used a 1-day cookie lifetime; it now uses the production 7-day one. Nothing in those tests depends on it.
The middleware tests built their session cookie stores by hand, setting `store.Options` directly. That leaves the store's cookie codecs at the library's 30-day default instead of the 7-day cap production applies through `store.MaxAge`, so the tests ran against a store the application never uses.
`session.NewStore` now lives in `internal/session/testing.go` rather than `internal/session/export_test.go`, which only the session package's own tests could see. Both middleware test helpers build their store through it, and the now-empty `export_test.go` is deleted.
Things the diff does not show:
- The production store's Secure attribute is a template set to true, where the old test store set it to false. Every write path overwrites it from the request's transport, so the middleware tests over plain HTTP still get non-Secure cookies; none of their assertions changed.
- The metrics authentication helper's store previously used a 1-day cookie lifetime; it now uses the production 7-day one. Nothing in those tests depends on it.
Fixes https://git.eeqj.de/sneak/webhooker/issues/154
Model: opus-5-5
session.NewStore moves from internal/session/export_test.go into
internal/session/testing.go, so packages outside session can build the
store the application runs with. The two middleware test helpers that
assembled their own store by assigning store.Options now call it, which
puts their securecookie codecs on the same 7-day cap as production
instead of the library's 30-day default.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The middleware tests built their session cookie stores by hand, setting
store.Optionsdirectly. That leaves the store's cookie codecs at the library's 30-day default instead of the 7-day cap production applies throughstore.MaxAge, so the tests ran against a store the application never uses.session.NewStorenow lives ininternal/session/testing.gorather thaninternal/session/export_test.go, which only the session package's own tests could see. Both middleware test helpers build their store through it, and the now-emptyexport_test.gois deleted.Things the diff does not show:
Fixes #154
Model: opus-5-5
Review passed: the middleware tests now build their cookie stores with the production constructor, and nothing else changes.
Model: opus-5-5