Files
Gitea/modules/setting/session_test.go
T
silverwind cf89ecd887 refactor!: move go-chi/session into Gitea (#39504)
The `gitea.com/go-chi/session` package only exists for Gitea, so it
moves into `modules/session` to fix its bugs directly. Fixes the flake
in
https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400.

- Sessions are only written back when changed, so a read-only request
can't revert a concurrent change or restore a logged-out session, like
https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12
- The session cookie is only set once a session holds data
- Every backend refreshes the expiry on load and file sessions are
written atomically
- Also fix  https://github.com/go-gitea/gitea/issues/36176

## ⚠️ BREAKING ⚠️

* the `mysql`, `postgres`, `couchbase` and `memcache` session providers
are removed, use `file`, `db` or `redis` instead
* login-related cookies are renamed to `gitea_session` and
`gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME`
and `COOKIE_REMEMBER_NAME` in app.ini

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-02 21:08:14 +02:00

90 lines
2.0 KiB
Go

// Copyright 2026 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package setting
import (
"testing"
"gitea.dev/modules/test"
"github.com/stretchr/testify/assert"
)
func TestSessionRedisSharedConnFallback(t *testing.T) {
tests := []struct {
name string
iniStr string
wantContain string
wantMissing string
}{
{
name: "redis provider with empty PROVIDER_CONFIG falls back to shared [redis]",
iniStr: `
[redis]
CONN_STR = redis://127.0.0.1:6379/0
[session]
PROVIDER = redis
`,
wantContain: "redis://127.0.0.1:6379/0",
},
{
name: "session PROVIDER_CONFIG wins over shared [redis]",
iniStr: `
[redis]
CONN_STR = redis://127.0.0.1:6379/0
[session]
PROVIDER = redis
PROVIDER_CONFIG = redis://10.0.0.1:6379/1
`,
wantContain: "redis://10.0.0.1:6379/1",
wantMissing: "127.0.0.1",
},
{
name: "no shared [redis]",
iniStr: `
[session]
PROVIDER = redis
`,
wantContain: "",
wantMissing: "redis://",
},
{
name: "file provider default path is untouched by shared [redis]",
iniStr: `
[redis]
CONN_STR = redis://127.0.0.1:6379/0
[session]
PROVIDER = file
`,
wantContain: "sessions",
wantMissing: "redis://",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
defer test.MockVariableValue(&Redis)()
cfg, err := NewConfigProviderFromData(tt.iniStr)
assert.NoError(t, err)
loadRedisFrom(cfg)
loadSessionFrom(cfg)
assert.Contains(t, SessionConfig.ProviderConfig, tt.wantContain)
if tt.wantMissing != "" {
assert.NotContains(t, SessionConfig.ProviderConfig, tt.wantMissing)
}
})
}
}
func TestSessionNonPositiveLifetimesUseDefaults(t *testing.T) {
defer test.MockVariableValue(&SessionConfig)()
for _, lifetime := range []string{"0", "-1"} {
cfg, err := NewConfigProviderFromData("[session]\nGC_INTERVAL_TIME = " + lifetime + "\nSESSION_LIFE_TIME = " + lifetime)
assert.NoError(t, err)
loadSessionFrom(cfg)
assert.EqualValues(t, 3600, SessionConfig.Gclifetime)
assert.EqualValues(t, 3600, SessionConfig.Maxlifetime)
}
}