check / check (push) Waiting to run
The middleware tests built their cookie stores by setting store.Options by hand, which left the securecookie codecs at the library's 30-day default instead of the 7-day cap production sets, an invisible divergence that would outlive the next change to store construction. The test store constructor moves from internal/session/export_test.go into internal/session/testing.go so other packages can reach it, and the two middleware test helpers build their stores through it. No test in the repo builds a cookie store by hand any more, and no assertion changes. Model: opus-5-5
47 lines
1.2 KiB
Go
47 lines
1.2 KiB
Go
package session
|
|
|
|
import (
|
|
"log/slog"
|
|
"time"
|
|
|
|
"github.com/gorilla/sessions"
|
|
"sneak.berlin/go/webhooker/internal/config"
|
|
)
|
|
|
|
// NewStore exposes the production cookie-store constructor so tests
|
|
// exercise the store the application actually runs with, rather than a
|
|
// lookalike assembled in the test.
|
|
func NewStore(key []byte) *sessions.CookieStore {
|
|
return newStore(key)
|
|
}
|
|
|
|
// NewForTest creates a Session with a pre-configured cookie store for use
|
|
// in tests. This bypasses the fx lifecycle and database dependency, allowing
|
|
// middleware and handler tests to use real session functionality. The key
|
|
// parameter is the raw 32-byte authentication key used for session encryption
|
|
// and CSRF cookie signing.
|
|
//
|
|
// The idle timeout is taken from cfg.SessionIdleTimeout, exactly as in
|
|
// production. The now parameter supplies the clock used for expiry
|
|
// checks so tests can advance time without sleeping; pass nil for the
|
|
// real clock.
|
|
func NewForTest(
|
|
store *sessions.CookieStore,
|
|
cfg *config.Config,
|
|
log *slog.Logger,
|
|
key []byte,
|
|
now func() time.Time,
|
|
) *Session {
|
|
if now == nil {
|
|
now = time.Now
|
|
}
|
|
|
|
return &Session{
|
|
store: store,
|
|
key: key,
|
|
log: log,
|
|
idleTimeout: cfg.SessionIdleTimeout,
|
|
now: now,
|
|
}
|
|
}
|