mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 09:40:48 +00:00
cf89ecd887
The `gitea.com/go-chi/session` package only exists for Gitea, so it moves into `modules/session` to fix its bugs directly. Fixes the flake in https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400. - Sessions are only written back when changed, so a read-only request can't revert a concurrent change or restore a logged-out session, like https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12 - The session cookie is only set once a session holds data - Every backend refreshes the expiry on load and file sessions are written atomically - Also fix https://github.com/go-gitea/gitea/issues/36176 ## ⚠️ BREAKING ⚠️ * the `mysql`, `postgres`, `couchbase` and `memcache` session providers are removed, use `file`, `db` or `redis` instead * login-related cookies are renamed to `gitea_session` and `gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME` and `COOKIE_REMEMBER_NAME` in app.ini --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
58 lines
1.6 KiB
Go
58 lines
1.6 KiB
Go
// Copyright 2019 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package integration
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"gitea.dev/modules/setting"
|
|
"gitea.dev/modules/test"
|
|
"gitea.dev/routers"
|
|
"gitea.dev/tests"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func getSessionID(resp *httptest.ResponseRecorder) string {
|
|
for _, cookie := range resp.Result().Cookies() {
|
|
if cookie.Name == setting.SessionConfig.CookieName {
|
|
return cookie.Value
|
|
}
|
|
}
|
|
return ""
|
|
}
|
|
|
|
func TestSessionFileCreation(t *testing.T) {
|
|
defer tests.PrepareTestEnv(t)()
|
|
tmpDir := t.TempDir()
|
|
defer test.MockVariableValue(&setting.SessionConfig.Provider, "file")()
|
|
defer test.MockVariableValue(&setting.SessionConfig.ProviderConfig, tmpDir)()
|
|
defer test.MockVariableValue(&testWebRoutes, routers.NormalRoutes())()
|
|
|
|
t.Run("NoSessionOnViewIssue", func(t *testing.T) {
|
|
defer tests.PrintCurrentTest(t)()
|
|
|
|
resp := MakeRequest(t, NewRequest(t, "GET", "/user2/repo1/issues/1"), http.StatusOK)
|
|
assert.Empty(t, getSessionID(resp))
|
|
})
|
|
t.Run("CreateSessionOnLogin", func(t *testing.T) {
|
|
defer tests.PrintCurrentTest(t)()
|
|
|
|
resp := MakeRequest(t, NewRequest(t, "GET", "/user/login"), http.StatusOK)
|
|
assert.Empty(t, getSessionID(resp))
|
|
|
|
req := NewRequestWithValues(t, "POST", "/user/login", map[string]string{
|
|
"user_name": "user2",
|
|
"password": userPassword,
|
|
})
|
|
sessionID := getSessionID(MakeRequest(t, req, http.StatusSeeOther))
|
|
require.Len(t, sessionID, 16)
|
|
assert.FileExists(t, filepath.Join(tmpDir, sessionID[0:1], sessionID[1:2], sessionID))
|
|
})
|
|
}
|