mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 10:50:50 +00:00
cf89ecd887
The `gitea.com/go-chi/session` package only exists for Gitea, so it moves into `modules/session` to fix its bugs directly. Fixes the flake in https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400. - Sessions are only written back when changed, so a read-only request can't revert a concurrent change or restore a logged-out session, like https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12 - The session cookie is only set once a session holds data - Every backend refreshes the expiry on load and file sessions are written atomically - Also fix https://github.com/go-gitea/gitea/issues/36176 ## ⚠️ BREAKING ⚠️ * the `mysql`, `postgres`, `couchbase` and `memcache` session providers are removed, use `file`, `db` or `redis` instead * login-related cookies are renamed to `gitea_session` and `gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME` and `COOKIE_REMEMBER_NAME` in app.ini --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
36 lines
964 B
Go
36 lines
964 B
Go
// Copyright 2023 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package integration
|
|
|
|
import (
|
|
"testing"
|
|
"time"
|
|
|
|
"gitea.dev/models/auth"
|
|
"gitea.dev/modules/timeutil"
|
|
"gitea.dev/tests"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func TestUpdateSession(t *testing.T) {
|
|
defer tests.PrintCurrentTest(t)()
|
|
defer timeutil.MockSet(time.Now())()
|
|
key := "0123456789abcdef"
|
|
for _, create := range []bool{true, true, false} {
|
|
require.NoError(t, auth.UpdateSession(t.Context(), key, []byte("data"), create))
|
|
}
|
|
sess, exist, err := auth.GetSession(t.Context(), key)
|
|
require.NoError(t, err)
|
|
require.True(t, exist)
|
|
assert.Equal(t, []byte("data"), sess.Data)
|
|
|
|
require.NoError(t, auth.DestroySession(t.Context(), key))
|
|
require.NoError(t, auth.UpdateSession(t.Context(), key, []byte("data"), false))
|
|
_, exist, err = auth.GetSession(t.Context(), key)
|
|
require.NoError(t, err)
|
|
assert.False(t, exist)
|
|
}
|