internal/httpd/cookieclear_test.go
39 lines · 1298 bytes
1package httpd
2
3import (
4 "net/http"
5 "testing"
6
7 "gitbay.org/gitbay/internal/config"
8)
9
10// A cookie that clears a session should carry the attributes the one that
11// set it carried. Deletion works without them, so this is consistency —
12// but a reviewer comparing the two paths should not have to work out
13// whether the difference is deliberate (go:S2092, go:S3330, #153).
14func TestClearCookieMirrorsTheSettingCall(t *testing.T) {
15 for _, tls := range []string{"acme", "off"} {
16 s := &Server{cfg: config.Config{}}
17 s.cfg.HTTP.TLS = tls
18 c := s.clearCookie(sessionCookie, http.SameSiteStrictMode)
19
20 if c.Value != "" || c.MaxAge >= 0 {
21 t.Errorf("tls=%s: not an expiring cookie: value=%q maxage=%d", tls, c.Value, c.MaxAge)
22 }
23 if !c.HttpOnly {
24 t.Errorf("tls=%s: clearing cookie is not HttpOnly", tls)
25 }
26 if c.SameSite != http.SameSiteStrictMode {
27 t.Errorf("tls=%s: SameSite = %v, want Strict", tls, c.SameSite)
28 }
29 if c.Path != "/" {
30 t.Errorf("tls=%s: Path = %q, want /", tls, c.Path)
31 }
32 // Secure follows TLS exactly as the setting calls do: forcing it
33 // on would make the cookie undeletable over plain HTTP, which is
34 // a supported deployment.
35 if want := tls != "off"; c.Secure != want {
36 t.Errorf("tls=%s: Secure = %v, want %v", tls, c.Secure, want)
37 }
38 }
39}