internal/httpd/cookieclear_test.go

61564b7c32807deb349e28f2b5c6909cb4143870
gitbay/internal/httpd/cookieclear_test.go history · blame · raw

39 lines · 1298 bytes

 1package httpd
 2
 3import (
 4	"net/http"
 5	"testing"
 6
 7	"gitbay.org/gitbay/internal/config"
 8)
 9
10// A cookie that clears a session should carry the attributes the one that
11// set it carried. Deletion works without them, so this is consistency —
12// but a reviewer comparing the two paths should not have to work out
13// whether the difference is deliberate (go:S2092, go:S3330, #153).
14func TestClearCookieMirrorsTheSettingCall(t *testing.T) {
15	for _, tls := range []string{"acme", "off"} {
16		s := &Server{cfg: config.Config{}}
17		s.cfg.HTTP.TLS = tls
18		c := s.clearCookie(sessionCookie, http.SameSiteStrictMode)
19
20		if c.Value != "" || c.MaxAge >= 0 {
21			t.Errorf("tls=%s: not an expiring cookie: value=%q maxage=%d", tls, c.Value, c.MaxAge)
22		}
23		if !c.HttpOnly {
24			t.Errorf("tls=%s: clearing cookie is not HttpOnly", tls)
25		}
26		if c.SameSite != http.SameSiteStrictMode {
27			t.Errorf("tls=%s: SameSite = %v, want Strict", tls, c.SameSite)
28		}
29		if c.Path != "/" {
30			t.Errorf("tls=%s: Path = %q, want /", tls, c.Path)
31		}
32		// Secure follows TLS exactly as the setting calls do: forcing it
33		// on would make the cookie undeletable over plain HTTP, which is
34		// a supported deployment.
35		if want := tls != "off"; c.Secure != want {
36			t.Errorf("tls=%s: Secure = %v, want %v", tls, c.Secure, want)
37		}
38	}
39}