Files
Gitea/tests/integration/create_no_session_test.go
T
silverwind cf89ecd887 refactor!: move go-chi/session into Gitea (#39504)
The `gitea.com/go-chi/session` package only exists for Gitea, so it
moves into `modules/session` to fix its bugs directly. Fixes the flake
in
https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400.

- Sessions are only written back when changed, so a read-only request
can't revert a concurrent change or restore a logged-out session, like
https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12
- The session cookie is only set once a session holds data
- Every backend refreshes the expiry on load and file sessions are
written atomically
- Also fix  https://github.com/go-gitea/gitea/issues/36176

## ⚠️ BREAKING ⚠️

* the `mysql`, `postgres`, `couchbase` and `memcache` session providers
are removed, use `file`, `db` or `redis` instead
* login-related cookies are renamed to `gitea_session` and
`gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME`
and `COOKIE_REMEMBER_NAME` in app.ini

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-02 21:08:14 +02:00

58 lines
1.6 KiB
Go

// Copyright 2019 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package integration
import (
"net/http"
"net/http/httptest"
"path/filepath"
"testing"
"gitea.dev/modules/setting"
"gitea.dev/modules/test"
"gitea.dev/routers"
"gitea.dev/tests"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
)
func getSessionID(resp *httptest.ResponseRecorder) string {
for _, cookie := range resp.Result().Cookies() {
if cookie.Name == setting.SessionConfig.CookieName {
return cookie.Value
}
}
return ""
}
func TestSessionFileCreation(t *testing.T) {
defer tests.PrepareTestEnv(t)()
tmpDir := t.TempDir()
defer test.MockVariableValue(&setting.SessionConfig.Provider, "file")()
defer test.MockVariableValue(&setting.SessionConfig.ProviderConfig, tmpDir)()
defer test.MockVariableValue(&testWebRoutes, routers.NormalRoutes())()
t.Run("NoSessionOnViewIssue", func(t *testing.T) {
defer tests.PrintCurrentTest(t)()
resp := MakeRequest(t, NewRequest(t, "GET", "/user2/repo1/issues/1"), http.StatusOK)
assert.Empty(t, getSessionID(resp))
})
t.Run("CreateSessionOnLogin", func(t *testing.T) {
defer tests.PrintCurrentTest(t)()
resp := MakeRequest(t, NewRequest(t, "GET", "/user/login"), http.StatusOK)
assert.Empty(t, getSessionID(resp))
req := NewRequestWithValues(t, "POST", "/user/login", map[string]string{
"user_name": "user2",
"password": userPassword,
})
sessionID := getSessionID(MakeRequest(t, req, http.StatusSeeOther))
require.Len(t, sessionID, 16)
assert.FileExists(t, filepath.Join(tmpDir, sessionID[0:1], sessionID[1:2], sessionID))
})
}