mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 22:40:39 +00:00
refactor!: move go-chi/session into Gitea (#39504)
The `gitea.com/go-chi/session` package only exists for Gitea, so it moves into `modules/session` to fix its bugs directly. Fixes the flake in https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400. - Sessions are only written back when changed, so a read-only request can't revert a concurrent change or restore a logged-out session, like https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12 - The session cookie is only set once a session holds data - Every backend refreshes the expiry on load and file sessions are written atomically - Also fix https://github.com/go-gitea/gitea/issues/36176 ## ⚠️ BREAKING ⚠️ * the `mysql`, `postgres`, `couchbase` and `memcache` session providers are removed, use `file`, `db` or `redis` instead * login-related cookies are renamed to `gitea_session` and `gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME` and `COOKIE_REMEMBER_NAME` in app.ini --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
+5
-10
@@ -40,19 +40,14 @@ func Init() {
|
||||
// handleSignInNonInteractive clears existing session variables and stores new ones for the specified user object
|
||||
// it is mainly for middleware sign-in which doesn't need user's interaction.
|
||||
func handleSignInNonInteractive(resp http.ResponseWriter, req *http.Request, sess SessionStore, user *user_model.User) {
|
||||
// We need to regenerate the session...
|
||||
newSess, err := session.RegenerateSession(resp, req)
|
||||
if err != nil {
|
||||
log.Error(fmt.Sprintf("Error regenerating session: %v", err))
|
||||
} else {
|
||||
sess = newSess
|
||||
}
|
||||
|
||||
sess.Regenerate(resp, req)
|
||||
ClearSessionKeysForSignIn(sess)
|
||||
err = sess.Set(session.KeyUID, user.ID)
|
||||
if err != nil {
|
||||
if err := sess.Set(session.KeyUID, user.ID); err != nil {
|
||||
log.Error(fmt.Sprintf("Error setting session: %v", err))
|
||||
}
|
||||
if err := sess.Release(); err != nil { // save before a long-lived handler like a websocket runs
|
||||
log.Error("Error saving session: %v", err)
|
||||
}
|
||||
|
||||
opts := &user_service.UpdateOptions{SetLastLogin: true}
|
||||
// Language setting of the user overwrites the one previously set
|
||||
|
||||
@@ -34,6 +34,16 @@ func TestReverseProxyIgnoresBot(t *testing.T) {
|
||||
assert.Nil(t, user)
|
||||
}
|
||||
|
||||
type releaseCountingStore struct {
|
||||
session.Store
|
||||
released int
|
||||
}
|
||||
|
||||
func (s *releaseCountingStore) Release() error {
|
||||
s.released++
|
||||
return s.Store.Release()
|
||||
}
|
||||
|
||||
func TestReverseProxyLastLogin(t *testing.T) {
|
||||
require.NoError(t, unittest.PrepareTestDatabase())
|
||||
defer test.MockVariableValue(&setting.ReverseProxyAuthUser, "X-WEBAUTH-USER")()
|
||||
@@ -41,13 +51,15 @@ func TestReverseProxyLastLogin(t *testing.T) {
|
||||
user := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 2})
|
||||
require.Zero(t, user.LastLoginUnix)
|
||||
|
||||
ctx, resp := contexttest.MockContext(t, "/", contexttest.MockContextOption{SessionStore: session.NewMockMemStore("reverse-proxy-last-login")})
|
||||
sess := &releaseCountingStore{Store: session.NewMockMemStore("reverse-proxy-last-login")}
|
||||
ctx, resp := contexttest.MockContext(t, "/", contexttest.MockContextOption{SessionStore: sess})
|
||||
ctx.Req.Header.Set(setting.ReverseProxyAuthUser, user.Name)
|
||||
rp := &ReverseProxy{CreateSession: true}
|
||||
|
||||
_, err := rp.Verify(ctx.Req, resp, ctx, ctx.Session)
|
||||
require.NoError(t, err)
|
||||
assert.NotZero(t, unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: user.ID}).LastLoginUnix)
|
||||
assert.Equal(t, 1, sess.released)
|
||||
|
||||
user.LastLoginUnix = 1
|
||||
require.NoError(t, user_model.UpdateUserCols(t.Context(), user, "last_login_unix"))
|
||||
@@ -55,4 +67,5 @@ func TestReverseProxyLastLogin(t *testing.T) {
|
||||
_, err = rp.Verify(ctx.Req, resp, ctx, ctx.Session)
|
||||
require.NoError(t, err)
|
||||
assert.EqualValues(t, 1, unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: user.ID}).LastLoginUnix) // no write without a new session
|
||||
assert.Equal(t, 1, sess.released)
|
||||
}
|
||||
|
||||
@@ -32,7 +32,6 @@ func (st *SessionsStore) New(r *http.Request, name string) (*sessions.Session, e
|
||||
return st.getOrNew(r, name, true)
|
||||
}
|
||||
|
||||
// getOrNew gets the session from the chi-session if it exists. Override permits the overriding of an unexpected object.
|
||||
func (st *SessionsStore) getOrNew(r *http.Request, name string, override bool) (*sessions.Session, error) {
|
||||
store := session_module.GetContextSession(r)
|
||||
|
||||
@@ -55,7 +54,7 @@ func (st *SessionsStore) getOrNew(r *http.Request, name string, override bool) (
|
||||
}
|
||||
|
||||
session.IsNew = override
|
||||
session.ID = store.ID() // Simply copy the session id from the chi store
|
||||
session.ID = store.ID()
|
||||
|
||||
return session, store.Set(name, session)
|
||||
}
|
||||
@@ -65,7 +64,7 @@ func (st *SessionsStore) Save(r *http.Request, w http.ResponseWriter, session *s
|
||||
store := session_module.GetContextSession(r)
|
||||
|
||||
if session.IsNew {
|
||||
_, _ = session_module.RegenerateSession(w, r)
|
||||
store.Regenerate(w, r)
|
||||
session.IsNew = false
|
||||
}
|
||||
|
||||
|
||||
@@ -149,16 +149,6 @@ func (b *Base) PlainText(status int, text string) {
|
||||
// Redirect redirects the request
|
||||
func (b *Base) Redirect(location string, status ...int) {
|
||||
code := util.OptionalArg(status, http.StatusSeeOther)
|
||||
|
||||
if !httplib.IsRelativeURL(location) {
|
||||
// Some browsers (Safari) have buggy behavior for Cookie + Cache + External Redirection, eg: /my-path => https://other/path
|
||||
// 1. the first request to "/my-path" contains cookie
|
||||
// 2. some time later, the request to "/my-path" doesn't contain cookie (caused by Prevent web tracking)
|
||||
// 3. Gitea's Sessioner doesn't see the session cookie, so it generates a new session id, and returns it to browser
|
||||
// 4. then the browser accepts the empty session, then the user is logged out
|
||||
// So in this case, we should remove the session cookie from the response header
|
||||
removeSessionCookieHeader(b.Resp)
|
||||
}
|
||||
// In case the request is made by "fetch-action" module, make JS redirect to the new location
|
||||
// Otherwise, the JS fetch will follow the redirection and read a "login" page, embed it to the current page, which is not expected.
|
||||
if httplib.IsGiteaFetchActionRequest(b.Req) {
|
||||
|
||||
@@ -21,27 +21,6 @@ func TestMain(m *testing.M) {
|
||||
|
||||
func TestRedirect(t *testing.T) {
|
||||
req, _ := http.NewRequest(http.MethodGet, "/", nil)
|
||||
|
||||
cases := []struct {
|
||||
url string
|
||||
keep bool
|
||||
}{
|
||||
{"http://test", false},
|
||||
{"https://test", false},
|
||||
{"//test", false},
|
||||
{"/://test", true},
|
||||
{"/test", true},
|
||||
}
|
||||
for _, c := range cases {
|
||||
resp := httptest.NewRecorder()
|
||||
b := NewBaseContextForTest(t, resp, req)
|
||||
resp.Header().Add("Set-Cookie", (&http.Cookie{Name: setting.SessionConfig.CookieName, Value: "dummy"}).String())
|
||||
b.Redirect(c.url)
|
||||
has := resp.Header().Get("Set-Cookie") == "i_like_gitea=dummy"
|
||||
assert.Equal(t, c.keep, has, "url = %q", c.url)
|
||||
}
|
||||
|
||||
req, _ = http.NewRequest(http.MethodGet, "/", nil)
|
||||
resp := httptest.NewRecorder()
|
||||
req.Header.Add("X-Gitea-Fetch-Action", "1")
|
||||
b := NewBaseContextForTest(t, resp, req)
|
||||
|
||||
@@ -4,26 +4,11 @@
|
||||
package context
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"gitea.dev/modules/setting"
|
||||
"gitea.dev/modules/web/middleware"
|
||||
)
|
||||
|
||||
const CookieNameFlash = "gitea_flash"
|
||||
|
||||
func removeSessionCookieHeader(w http.ResponseWriter) {
|
||||
cookies := w.Header()["Set-Cookie"]
|
||||
w.Header().Del("Set-Cookie")
|
||||
for _, cookie := range cookies {
|
||||
if strings.HasPrefix(cookie, setting.SessionConfig.CookieName+"=") {
|
||||
continue
|
||||
}
|
||||
w.Header().Add("Set-Cookie", cookie)
|
||||
}
|
||||
}
|
||||
|
||||
// SetSiteCookie convenience function to set most cookies consistently
|
||||
func (ctx *Context) SetSiteCookie(name, value string, maxAge int) {
|
||||
middleware.SetSiteCookie(ctx.Resp, name, value, maxAge)
|
||||
|
||||
@@ -18,16 +18,6 @@ import (
|
||||
"github.com/stretchr/testify/assert"
|
||||
)
|
||||
|
||||
func TestRemoveSessionCookieHeader(t *testing.T) {
|
||||
w := httptest.NewRecorder()
|
||||
w.Header().Add("Set-Cookie", (&http.Cookie{Name: setting.SessionConfig.CookieName, Value: "foo"}).String())
|
||||
w.Header().Add("Set-Cookie", (&http.Cookie{Name: "other", Value: "bar"}).String())
|
||||
assert.Len(t, w.Header().Values("Set-Cookie"), 2)
|
||||
removeSessionCookieHeader(w)
|
||||
assert.Len(t, w.Header().Values("Set-Cookie"), 1)
|
||||
assert.Contains(t, "other=bar", w.Header().Get("Set-Cookie"))
|
||||
}
|
||||
|
||||
func TestServerErrorFetchActionRespondsJSON(t *testing.T) {
|
||||
req, _ := http.NewRequest(http.MethodPost, "/", nil)
|
||||
req.Header.Add("X-Gitea-Fetch-Action", "1")
|
||||
|
||||
@@ -70,7 +70,7 @@ func MockContext(t *testing.T, reqPath string, opts ...MockContextOption) (*cont
|
||||
ctx := context.NewWebContext(base, opt.Render, nil)
|
||||
ctx.SetContextValue(chi.RouteCtxKey, chiCtx)
|
||||
if opt.SessionStore != nil {
|
||||
ctx.SetContextValue(session.MockStoreContextKey, opt.SessionStore)
|
||||
ctx.SetContextValue(session.ContextKey, opt.SessionStore)
|
||||
ctx.Session = opt.SessionStore
|
||||
}
|
||||
ctx.Cache = cache.GetCache()
|
||||
|
||||
Reference in New Issue
Block a user