mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 08:30:46 +00:00
cf89ecd887
The `gitea.com/go-chi/session` package only exists for Gitea, so it moves into `modules/session` to fix its bugs directly. Fixes the flake in https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400. - Sessions are only written back when changed, so a read-only request can't revert a concurrent change or restore a logged-out session, like https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12 - The session cookie is only set once a session holds data - Every backend refreshes the expiry on load and file sessions are written atomically - Also fix https://github.com/go-gitea/gitea/issues/36176 ## ⚠️ BREAKING ⚠️ * the `mysql`, `postgres`, `couchbase` and `memcache` session providers are removed, use `file`, `db` or `redis` instead * login-related cookies are renamed to `gitea_session` and `gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME` and `COOKIE_REMEMBER_NAME` in app.ini --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
78 lines
3.0 KiB
Go
78 lines
3.0 KiB
Go
// Copyright 2019 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package setting
|
|
|
|
import (
|
|
"cmp"
|
|
"net/http"
|
|
"path/filepath"
|
|
"strings"
|
|
|
|
"gitea.dev/modules/util"
|
|
)
|
|
|
|
// SessionConfig defines Session settings
|
|
var SessionConfig = struct {
|
|
Provider string
|
|
// Provider configuration, it's corresponding to provider.
|
|
ProviderConfig string
|
|
// Cookie name to save session ID. Default is "MacaronSession".
|
|
CookieName string
|
|
// Cookie path to store. Default is "/".
|
|
CookiePath string
|
|
// GC interval time in seconds. Default is 3600.
|
|
Gclifetime int64
|
|
// Max life time in seconds. Default is whatever GC interval time is.
|
|
Maxlifetime int64
|
|
// Use HTTPS only. Default is false.
|
|
Secure bool
|
|
// Cookie domain name. Default is empty.
|
|
Domain string
|
|
// SameSite declares if your cookie should be restricted to a first-party or same-site context. Valid strings are "none", "lax", "strict". Default is "lax"
|
|
SameSite http.SameSite
|
|
}{
|
|
Provider: "memory", // the "Install" page doesn't load the [session] config
|
|
CookieName: "gitea_session",
|
|
Gclifetime: 86400,
|
|
Maxlifetime: 86400,
|
|
SameSite: http.SameSiteLaxMode,
|
|
}
|
|
|
|
func loadSessionFrom(rootCfg ConfigProvider) {
|
|
sec := rootCfg.Section("session")
|
|
SessionConfig.Provider = sec.Key("PROVIDER").MustString("file")
|
|
|
|
switch SessionConfig.Provider {
|
|
case "redis":
|
|
SessionConfig.ProviderConfig = sec.Key("PROVIDER_CONFIG").MustString(Redis.ConnStr)
|
|
case "file":
|
|
SessionConfig.ProviderConfig = sec.Key("PROVIDER_CONFIG").MustString(filepath.Join(AppDataPath, "sessions"))
|
|
if !filepath.IsAbs(SessionConfig.ProviderConfig) {
|
|
// Although the "data path" should be used as Gitea's "data" base directory (work path sometimes is not writable),
|
|
// document says the relative session path is based on the "work path", so keep the behavior
|
|
SessionConfig.ProviderConfig = filepath.Join(AppWorkPath, SessionConfig.ProviderConfig)
|
|
}
|
|
checkOverlappedPath("[session].PROVIDER_CONFIG", SessionConfig.ProviderConfig)
|
|
default:
|
|
SessionConfig.ProviderConfig = sec.Key("PROVIDER_CONFIG").String()
|
|
}
|
|
|
|
SessionConfig.CookieName = sec.Key("COOKIE_NAME").MustString("gitea_session")
|
|
// HINT: INSTALL-PAGE-COOKIE-INIT: the cookie system is not properly initialized on the "Install" page, so there is no CookiePath
|
|
SessionConfig.CookiePath = util.IfZero(AppSubURL, "/")
|
|
SessionConfig.Secure = sec.Key("COOKIE_SECURE").MustBool(strings.HasPrefix(strings.ToLower(AppURL), "https://"))
|
|
SessionConfig.Gclifetime = cmp.Or(max(sec.Key("GC_INTERVAL_TIME").MustInt64(86400), 0), 3600)
|
|
SessionConfig.Maxlifetime = cmp.Or(max(sec.Key("SESSION_LIFE_TIME").MustInt64(86400), 0), SessionConfig.Gclifetime)
|
|
SessionConfig.Domain = sec.Key("DOMAIN").String()
|
|
samesiteString := sec.Key("SAME_SITE").In("lax", []string{"none", "lax", "strict"})
|
|
switch strings.ToLower(samesiteString) {
|
|
case "none":
|
|
SessionConfig.SameSite = http.SameSiteNoneMode
|
|
case "strict":
|
|
SessionConfig.SameSite = http.SameSiteStrictMode
|
|
default:
|
|
SessionConfig.SameSite = http.SameSiteLaxMode
|
|
}
|
|
}
|