internal/httpd/logincookie_test.go

72920bdf0504bcee3d15305abc0724ae216d088c
gitbay/internal/httpd/logincookie_test.go history · blame · raw

38 lines · 1237 bytes

 1package httpd
 2
 3import (
 4	"net/http"
 5	"testing"
 6
 7	"gitbay.org/gitbay/internal/config"
 8)
 9
10// The session cookie must be Lax, not Strict. A login link clicked in a mail
11// client is a cross-site top-level navigation, and Strict can withhold the
12// cookie through the redirect that follows, so the visitor lands logged out
13// (#155). Cross-site POSTs stay protected: Lax withholds the cookie from them,
14// and checkOrigin refuses them besides.
15//
16// The other two attributes are what keep the token out of a script's reach
17// and off the wire in clear, so they are asserted on the same literal login
18// hands to http.SetCookie.
19func TestSessionCookieAttributes(t *testing.T) {
20	if sessionSameSite != http.SameSiteLaxMode {
21		t.Errorf("sessionSameSite = %v, want Lax", sessionSameSite)
22	}
23	for _, tls := range []string{"acme", "off"} {
24		s := &Server{cfg: config.Config{}}
25		s.cfg.HTTP.TLS = tls
26		c := s.sessionCookieFor("tok")
27
28		if c.SameSite != http.SameSiteLaxMode {
29			t.Errorf("tls=%s: SameSite = %v, want Lax", tls, c.SameSite)
30		}
31		if !c.HttpOnly {
32			t.Errorf("tls=%s: session cookie is not HttpOnly", tls)
33		}
34		if want := tls != "off"; c.Secure != want {
35			t.Errorf("tls=%s: Secure = %v, want %v", tls, c.Secure, want)
36		}
37	}
38}