internal/httpd/cookieclear_test.go
38 lines · 1283 bytes
1package httpd
2
3import (
4 "testing"
5
6 "gitbay.org/gitbay/internal/config"
7)
8
9// A cookie that clears a session should carry the attributes the one that
10// set it carried. Deletion works without them, so this is consistency —
11// but a reviewer comparing the two paths should not have to work out
12// whether the difference is deliberate (go:S2092, go:S3330, #153).
13func TestClearCookieMirrorsTheSettingCall(t *testing.T) {
14 for _, tls := range []string{"acme", "off"} {
15 s := &Server{cfg: config.Config{}}
16 s.cfg.HTTP.TLS = tls
17 c := s.clearCookie(sessionCookie, sessionSameSite)
18
19 if c.Value != "" || c.MaxAge >= 0 {
20 t.Errorf("tls=%s: not an expiring cookie: value=%q maxage=%d", tls, c.Value, c.MaxAge)
21 }
22 if !c.HttpOnly {
23 t.Errorf("tls=%s: clearing cookie is not HttpOnly", tls)
24 }
25 if c.SameSite != sessionSameSite {
26 t.Errorf("tls=%s: SameSite = %v, want %v", tls, c.SameSite, sessionSameSite)
27 }
28 if c.Path != "/" {
29 t.Errorf("tls=%s: Path = %q, want /", tls, c.Path)
30 }
31 // Secure follows TLS exactly as the setting calls do: forcing it
32 // on would make the cookie undeletable over plain HTTP, which is
33 // a supported deployment.
34 if want := tls != "off"; c.Secure != want {
35 t.Errorf("tls=%s: Secure = %v, want %v", tls, c.Secure, want)
36 }
37 }
38}