internal/httpd/cookieclear_test.go

v1.22.0
gitbay/internal/httpd/cookieclear_test.go history · blame · raw

38 lines · 1283 bytes

 1package httpd
 2
 3import (
 4	"testing"
 5
 6	"gitbay.org/gitbay/internal/config"
 7)
 8
 9// A cookie that clears a session should carry the attributes the one that
10// set it carried. Deletion works without them, so this is consistency —
11// but a reviewer comparing the two paths should not have to work out
12// whether the difference is deliberate (go:S2092, go:S3330, #153).
13func TestClearCookieMirrorsTheSettingCall(t *testing.T) {
14	for _, tls := range []string{"acme", "off"} {
15		s := &Server{cfg: config.Config{}}
16		s.cfg.HTTP.TLS = tls
17		c := s.clearCookie(sessionCookie, sessionSameSite)
18
19		if c.Value != "" || c.MaxAge >= 0 {
20			t.Errorf("tls=%s: not an expiring cookie: value=%q maxage=%d", tls, c.Value, c.MaxAge)
21		}
22		if !c.HttpOnly {
23			t.Errorf("tls=%s: clearing cookie is not HttpOnly", tls)
24		}
25		if c.SameSite != sessionSameSite {
26			t.Errorf("tls=%s: SameSite = %v, want %v", tls, c.SameSite, sessionSameSite)
27		}
28		if c.Path != "/" {
29			t.Errorf("tls=%s: Path = %q, want /", tls, c.Path)
30		}
31		// Secure follows TLS exactly as the setting calls do: forcing it
32		// on would make the cookie undeletable over plain HTTP, which is
33		// a supported deployment.
34		if want := tls != "off"; c.Secure != want {
35			t.Errorf("tls=%s: Secure = %v, want %v", tls, c.Secure, want)
36		}
37	}
38}